CVE-2026-31256
HIGHMERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n - Denial of Service via RTSP SETUP Transport Header
Title source: llmDescription
A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rtsp://<IP>:554/stream1/track2, the device fails to properly validate the Transport header field. When this header is improperly constructed, the RTSP service can dereference a NULL pointer during request parsing. Successful exploitation causes the device to crash and automatically reboot.
References (1)
Core 1
Scores
CVSS v3
7.5
EPSS
0.0041
EPSS Percentile
32.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-476
Status
published
Products (1)
mercurycom/mipc252w_firmware
1.0.5 build_230306
Published
Apr 27, 2026
Tracked Since
Apr 28, 2026