Executive brief
The MERCURY MIPC252W IP camera is a security device used for video monitoring. A vulnerability in its video streaming service allows an attacker on the same local network to disable the camera's streaming capabilities for specific users. By sending specially malformed requests, an attacker can trick the camera into locking out legitimate users' IP addresses, preventing them from viewing the video feed for several hours.
Technical details
An input validation vulnerability (CWE-20) exists in the RTSP service of the MERCURY MIPC252W IP camera. The device fails to properly validate the URL field in the RTSP DESCRIBE request line, allowing malformed URLs to bypass parsing and enter authentication logic. This leads to two failure modes: first, the protocol state machine becomes corrupted, causing CSeq mismatches and subsequent '400 Bad Request' errors on the connection. Second, the device erroneously counts these malformed requests as authentication failures. By sending repeated malformed requests, an attacker can trigger an IP-level lockout that prevents the targeted IP address from accessing the RTSP service for 40 minutes to several hours. This attack requires no authentication and is reachable via the local network.
Affected products
- MERCURY MIPC252W IP Camera 1.0.5 Build 230306 Rel.79931n
Timeline
- 2026-07-09: disclosed: Initial vulnerability report and CVE assignment.
- 2026-07-09: advisory