CVE-2026-26340
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
24/02/2026
Last modified:
26/02/2026
Description
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized disclosure of surveillance data.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tattile:smart\+_firmware:*:*:*:*:*:*:*:* | 1.181.5 (including) | |
| cpe:2.3:h:tattile:smart\+:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tattile:tolling\+_firmware:*:*:*:*:*:*:*:* | 1.181.5 (including) | |
| cpe:2.3:h:tattile:tolling\+:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tattile:smart\+_speed_firmware:*:*:*:*:*:*:*:* | 1.181.5 (including) | |
| cpe:2.3:h:tattile:smart\+_speed:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tattile:smart\+_traffic_light_firmware:*:*:*:*:*:*:*:* | 1.181.5 (including) | |
| cpe:2.3:h:tattile:smart\+_traffic_light:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tattile:axle_counter_firmware:*:*:*:*:*:*:*:* | 1.181.5 (including) | |
| cpe:2.3:h:tattile:axle_counter:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tattile:vega53_firmware:*:*:*:*:*:*:*:* | 1.181.5 (including) | |
| cpe:2.3:h:tattile:vega53:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tattile:vega33_firmware:*:*:*:*:*:*:*:* | 1.181.5 (including) | |
| cpe:2.3:h:tattile:vega33:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tattile:vega11_firmware:*:*:*:*:*:*:*:* | 1.181.5 (including) |
To consult the complete list of CPE names with products and versions, see this page



