VYPR

Mipc252w Firmware

by Mercurycom

CVEs (4)

  • CVE-2026-35903CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.00

    MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, the device does not verify the Digest response parameter in subsequent RTSP…

  • CVE-2026-31256HigApr 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rtsp://:554/stream1/track2, the device fails to properly validate the Transport header field. When…

  • CVE-2026-35902MedApr 27, 2026
    risk 0.40cvss 6.2epss 0.00

    The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication parameters, an unauthenticated attacker can cause the RTSP service to enter a persistent…

  • CVE-2026-35901MedApr 27, 2026
    risk 0.29cvss 4.4epss 0.00

    A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly sending SETUP requests for the same media track within a single RTSP session. This causes the server to reset…