The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication parameters, an unauthenticated attacker can cause the RTSP service to enter a persistent authentication failure state, preventing legitimate clients from authenticating and leading to a denial of service.
Metrics
Affected Vendors & Products
References
History
Tue, 05 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mercurycom
Mercurycom mipc252w Mercurycom mipc252w Firmware |
|
| CPEs | cpe:2.3:h:mercurycom:mipc252w:-:*:*:*:*:*:*:* cpe:2.3:o:mercurycom:mipc252w_firmware:1.0.5:build_230306:*:*:*:*:*:* |
|
| Vendors & Products |
Mercurycom
Mercurycom mipc252w Mercurycom mipc252w Firmware |
Wed, 29 Apr 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Denial of Service via Persistent Digest Authentication Failure in MERCURY MIPC252W RTSP Service |
Wed, 29 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Denial of Service via Persistent Authentication Failure in MIPC252W RTSP Service | |
| Weaknesses | CWE-519 CWE-770 |
Tue, 28 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-307 | |
| Metrics |
cvssV3_1
|
Tue, 28 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Denial of Service via Persistent Authentication Failure in MIPC252W RTSP Service | |
| Weaknesses | CWE-519 CWE-770 |
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mercury
Mercury mipc252w |
|
| Vendors & Products |
Mercury
Mercury mipc252w |
Mon, 27 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication parameters, an unauthenticated attacker can cause the RTSP service to enter a persistent authentication failure state, preventing legitimate clients from authenticating and leading to a denial of service. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-04-27T00:00:00.000Z
Updated: 2026-04-28T12:52:39.002Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-35902
Updated: 2026-04-28T12:52:28.333Z
Status : Analyzed
Published: 2026-04-27T19:16:51.060
Modified: 2026-05-05T13:40:59.077
Link: CVE-2026-35902
No data.