CVE-2017-10796

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
02/07/2017
Last modified:
20/04/2025

Description

On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp URL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tp-link:nc250_firmware:*:*:*:*:*:*:*:* 1.2.1 (including)
cpe:2.3:h:tp-link:nc250:-:*:*:*:*:*:*:*