CVE-2026-51597

MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass authentication without knowledge of the device credentials, gaining unauthorized access to the live video stream.
Configurations

No configuration.

History

10 Jul 2026, 18:16

Type Values Removed Values Added
CWE CWE-294
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
References () https://github.com/kkkk2222874/cve_ID_report/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_5th/README.md - () https://github.com/kkkk2222874/cve_ID_report/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_5th/README.md -

09 Jul 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-09 17:16

Updated : 2026-07-10 18:51


NVD link : CVE-2026-51597

Mitre link : CVE-2026-51597

CVE.ORG link : CVE-2026-51597


JSON object : View

Products Affected

No product.

CWE
CWE-294

Authentication Bypass by Capture-replay