CVE-2021-26627

HIGH

qcp200w_firmware - Unauthenticated Real-Time Image Information Exposure via RTSP Port

Title source: llm
STIX 2.1

Description

Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerability could allow to remote attackers to send the RTSP requests using ffplay command and lead to leakage a live image.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0134
EPSS Percentile 67.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-284 CWE-287
Status published
Products (1)
qcp/qcp200w_firmware (2 CPE variants)
Published Apr 19, 2022
Tracked Since Feb 18, 2026