Записи mercurycom
13 опубликованных записей вендора mercurycom.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-400 Uncontrolled Resource Consumption1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2023-46518Эксплойта нет | Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB.mercurycom · a15 firmware · CWE-787 | Критическая9,8 | — | 1,8 % | 25 окт. 2023 г. |
39Наблюдать | CVE-2026-35903Эксплойта нет | MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service.mercurycom · mipc252w firmware · CWE-287 | Критическая9,8 | — | 0,6 % | 27 апр. 2026 г. |
39Наблюдать | CVE-2025-50401Эксплойта нет | Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter password.mercurycom · d196g firmware · CWE-120 | Критическая9,8 | — | 0,4 % | 16 дек. 2025 г. |
39Наблюдать | CVE-2025-50398Эксплойта нет | Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter fac_passwordmercurycom · d196g firmware · CWE-120 | Критическая9,8 | — | 0,4 % | 16 дек. 2025 г. |
36Наблюдать | CVE-2022-31849Эксплойта нет | MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable mercurycom · mipc451-4 firmware | Высокая8,8 | — | 1,9 % | 16 июн. 2022 г. |
32Наблюдать | CVE-2021-27825Proof of concept | A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL.mercurycom · mac1200r firmware · CWE-22 | Высокая7,5 | — | 7,8 % | 29 мая 2023 г. |
30Наблюдать | CVE-2026-31256Эксплойта нет | A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n.mercurycom · mipc252w firmware · CWE-476 | Высокая7,5 | — | 0,5 % | 27 апр. 2026 г. |
27Наблюдать | CVE-2024-8655Эксплойта нет | Mercury MNVR816 web-static file accessmercury · mnvr816 · CWE-552 | Средняя6,9 | — | 0,5 % | 10 сент. 2024 г. |
26Наблюдать | CVE-2012-4999Proof of concept | Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted stmercurycom · mr804 firmware · CWE-20 | Средняя6,1 | — | 6,6 % | 19 сент. 2012 г. |
26Наблюдать | CVE-2025-65288Эксплойта нет | A buffer overflow in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) occurs when the device accepts and stores excessively longmercurycom · mr816 firmware · CWE-120 | Средняя6,5 | — | 0,4 % | 9 дек. 2025 г. |
24Наблюдать | CVE-2025-65289Эксплойта нет | A stored Cross site scripting (XSS) vulnerability in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) router allows a remote attmercurycom · mr816 firmware · CWE-79 | Средняя6,1 | — | 0,3 % | 9 дек. 2025 г. |
24Наблюдать | CVE-2026-35902Эксплойта нет | The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts.mercurycom · mipc252w firmware · CWE-307 | Средняя6,2 | — | 0,2 % | 27 апр. 2026 г. |
17Наблюдать | CVE-2026-35901Эксплойта нет | A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger sessimercurycom · mipc252w firmware · CWE-400 | Средняя4,4 | — | 0,2 % | 27 апр. 2026 г. |
- CVE-2023-4651840В плане
Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mercurycom · a15 firmware25 окт. 2023 г.
- CVE-2026-3590339Наблюдать
MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mercurycom · mipc252w firmware27 апр. 2026 г.
- CVE-2025-5040139Наблюдать
Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter password.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %mercurycom · d196g firmware16 дек. 2025 г.
- CVE-2025-5039839Наблюдать
Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter fac_password
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %mercurycom · d196g firmware16 дек. 2025 г.
- CVE-2022-3184936Наблюдать
MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %mercurycom · mipc451-4 firmware16 июн. 2022 г.
- CVE-2021-2782532Наблюдать
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL.
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %mercurycom · mac1200r firmware29 мая 2023 г.
- CVE-2026-3125630Наблюдать
A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %mercurycom · mipc252w firmware27 апр. 2026 г.
- CVE-2024-865527Наблюдать
Mercury MNVR816 web-static file access
СредняяCVSS 6,9Эксплойта нетEPSS 0 %mercury · mnvr81610 сент. 2024 г.
- CVE-2012-499926Наблюдать
Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted st
СредняяCVSS 6,1Proof of conceptEPSS 7 %mercurycom · mr804 firmware19 сент. 2012 г.
- CVE-2025-6528826Наблюдать
A buffer overflow in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) occurs when the device accepts and stores excessively long
СредняяCVSS 6,5Эксплойта нетEPSS 0 %mercurycom · mr816 firmware9 дек. 2025 г.
- CVE-2025-6528924Наблюдать
A stored Cross site scripting (XSS) vulnerability in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) router allows a remote att
СредняяCVSS 6,1Эксплойта нетEPSS 0 %mercurycom · mr816 firmware9 дек. 2025 г.
- CVE-2026-3590224Наблюдать
The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts.
СредняяCVSS 6,2Эксплойта нетEPSS 0 %mercurycom · mipc252w firmware27 апр. 2026 г.
- CVE-2026-3590117Наблюдать
A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger sessi
СредняяCVSS 4,4Эксплойта нетEPSS 0 %mercurycom · mipc252w firmware27 апр. 2026 г.