High severity7.5NVD Advisory· Published Feb 24, 2026· Updated Jun 17, 2026
CVE-2026-26340
CVE-2026-26340
Description
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized disclosure of surveillance data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- cpe:2.3:o:tattile:axle_counter_firmware:*:*:*:*:*:*:*:*Range: <=1.181.5
- cpe:2.3:o:tattile:smart\+_speed_firmware:*:*:*:*:*:*:*:*Range: <=1.181.5
- cpe:2.3:o:tattile:smart\+_traffic_light_firmware:*:*:*:*:*:*:*:*Range: <=1.181.5
- Tattile s.r.l./Smart+ Traffic Lightv5Range: 0
- Range: 0
- Range: 0
0+ 1 more
- (no CPE)range: 0
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
3- www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5978.phpnvdExploitThird Party Advisory
- www.vulncheck.com/advisories/tattile-smart-vega-basic-unauthenticated-rtsp-stream-disclosurenvdThird Party AdvisoryVDB Entry
- www.tattile.comnvdProduct
News mentions
0No linked articles in our index yet.