A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the component RTSP Live Video Stream Endpoint. Such manipulation leads to improper authentication. The attack must be carried out from within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
| Link | Resource |
|---|---|
| https://github.com/pwnpwnpur1n/IoT-advisories/blob/main/TC155-Unauth-RTSP.md | Exploit Third Party Advisory |
| https://vuldb.com/?ctiid.336519 | Permissions Required VDB Entry |
| https://vuldb.com/?id.336519 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.707195 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
| AND |
|
History
18 Dec 2025, 21:23
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:shenzhenningyuandatechnology:tc155_firmware:57.0.2.0:*:*:*:*:*:*:* cpe:2.3:h:shenzhenningyuandatechnology:tc155:-:*:*:*:*:*:*:* |
|
| First Time |
Shenzhenningyuandatechnology tc155 Firmware
Shenzhenningyuandatechnology Shenzhenningyuandatechnology tc155 |
|
| References | () https://github.com/pwnpwnpur1n/IoT-advisories/blob/main/TC155-Unauth-RTSP.md - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/?ctiid.336519 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.336519 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.707195 - Third Party Advisory, VDB Entry |
16 Dec 2025, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-16 03:15
Updated : 2025-12-18 21:23
NVD link : CVE-2025-14746
Mitre link : CVE-2025-14746
CVE.ORG link : CVE-2025-14746
JSON object : View
Products Affected
shenzhenningyuandatechnology
- tc155
- tc155_firmware
CWE
CWE-287
Improper Authentication
