Junglewise Threat Intelligence

CVE-2026-51599: MERCURY MIPC252W insufficient input validation in RTSP service

CVE-2026-51599 · Severity: info · CVSS 5.3 · Published 2026-07-09

Executive brief

A security flaw has been identified in the MERCURY MIPC252W smart camera, which uses the RTSP protocol to stream video. An attacker can send a specially crafted request that causes the camera's communication service to hang, making that specific connection unusable until it times out. While this primarily affects individual connections rather than the entire device, it could be used to interfere with video monitoring services.

Technical details

An insufficient input validation vulnerability exists in the RTSP service of the MERCURY MIPC252W camera (v1.0.5 Build 230306 Rel.79931n). The RTSP parser fails to properly handle requests that include a 'Content-Length' header but lack a corresponding message body. Instead of rejecting the malformed request, the parser enters a 'body-waiting' state, causing it to silently consume all subsequent data on that TCP connection as if it were part of the missing body. This state persists until a server-side timeout occurs, effectively resulting in a localized denial-of-service for that specific connection. No authentication is required to trigger this behavior.

Affected products

  • MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n

Timeline

  • 2026-07-09: disclosed
  • 2026-07-09: advisory

References

Related threats