Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-51599: MERCURY MIPC252W RTSP Service Connection Disruption
CVE-2026-51599
CVE-2026-51599
Summary
An attacker can send a malicious request to the MERCURY MIPC252W's RTSP service, causing it to temporarily stop working for other users. This can happen without the attacker needing a password. To protect your system, update the MERCURY MIPC252W software to the latest version.
Original title
An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connectio...
Original description
An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a Content-Length header but no corresponding message body. The affected RTSP parser enters a body-waiting state instead of rejecting the malformed request, causing all subsequent data on the connection to be silently consumed as body content until a server-side timeout closes the connection.
Vulnerability type
CWE-20
Improper Input Validation
Published: 9 Jul 2026 · Updated: 20 Jul 2026 · First seen: 9 Jul 2026