CVE-2026-51599

CRITICAL

MERCURY MIPC252W 1.0.5 Build 230306 - Unauthenticated Denial of Service via RTSP Content-Length Header Parsing

Title source: llm
STIX 2.1

Description

An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a Content-Length header but no corresponding message body. The affected RTSP parser enters a body-waiting state instead of rejecting the malformed request, causing all subsequent data on the connection to be silently consumed as body content until a server-side timeout closes the connection.

Scores

CVSS v3 9.8
EPSS 0.0043
EPSS Percentile 35.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-20
Status published
Published Jul 09, 2026
Tracked Since Jul 09, 2026