Junglewise Threat Intelligence

CVE-2026-51598: MERCURY MIPC252W input validation vulnerability in RTSP service

CVE-2026-51598 · Severity: info · CVSS 4.3 · Published 2026-07-09

Executive brief

The MERCURY MIPC252W IP camera is a security device used for video monitoring. A vulnerability in its video streaming service allows an attacker on the same local network to disable the camera's streaming capabilities for specific users. By sending specially malformed requests, an attacker can trick the camera into locking out legitimate users' IP addresses, preventing them from viewing the video feed for several hours.

Technical details

An input validation vulnerability (CWE-20) exists in the RTSP service of the MERCURY MIPC252W IP camera. The device fails to properly validate the URL field in the RTSP DESCRIBE request line, allowing malformed URLs to bypass parsing and enter authentication logic. This leads to two failure modes: first, the protocol state machine becomes corrupted, causing CSeq mismatches and subsequent '400 Bad Request' errors on the connection. Second, the device erroneously counts these malformed requests as authentication failures. By sending repeated malformed requests, an attacker can trigger an IP-level lockout that prevents the targeted IP address from accessing the RTSP service for 40 minutes to several hours. This attack requires no authentication and is reachable via the local network.

Affected products

  • MERCURY MIPC252W IP Camera 1.0.5 Build 230306 Rel.79931n

Timeline

  • 2026-07-09: disclosed: Initial vulnerability report and CVE assignment.
  • 2026-07-09: advisory

References