CVE-2024-42531: n/a
Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. NOTE: the vendor's perspective is that the Anonymous120386 sample code can establish RTSP protocol communictaion, but cannot obtain video or audio data; thus, there is no risk.
AI Analysis
Technical Summary
CVE-2024-42531 describes a vulnerability in the Ezviz Internet PT Camera CS-CV246 D15655150 where an unauthenticated attacker can send crafted RTSP packets with particular URLs to redirect the camera feed and access the live video stream. Despite the high CVSS score of 9.8 indicating critical severity, the vendor's assessment clarifies that the provided sample code can only establish RTSP communication but does not allow retrieval of video or audio data, effectively negating the risk of unauthorized video access. There is no patch or remediation information available, and the device is not a cloud service.
Potential Impact
If exploitable as initially described, the vulnerability would allow unauthenticated attackers to access live video streams, compromising confidentiality, integrity, and availability of the camera feed. However, the vendor's perspective indicates that actual video or audio data cannot be obtained through the demonstrated method, meaning the practical impact is nullified. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vendor states that the sample code cannot obtain video or audio data, implying no immediate risk and no action required at this time. Monitor vendor communications for updates or official fixes.
CVE-2024-42531: n/a
Description
Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. NOTE: the vendor's perspective is that the Anonymous120386 sample code can establish RTSP protocol communictaion, but cannot obtain video or audio data; thus, there is no risk.
CVSS v3.1
Score 9.8critical
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-42531 describes a vulnerability in the Ezviz Internet PT Camera CS-CV246 D15655150 where an unauthenticated attacker can send crafted RTSP packets with particular URLs to redirect the camera feed and access the live video stream. Despite the high CVSS score of 9.8 indicating critical severity, the vendor's assessment clarifies that the provided sample code can only establish RTSP communication but does not allow retrieval of video or audio data, effectively negating the risk of unauthorized video access. There is no patch or remediation information available, and the device is not a cloud service.
Potential Impact
If exploitable as initially described, the vulnerability would allow unauthenticated attackers to access live video streams, compromising confidentiality, integrity, and availability of the camera feed. However, the vendor's perspective indicates that actual video or audio data cannot be obtained through the demonstrated method, meaning the practical impact is nullified. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vendor states that the sample code cannot obtain video or audio data, implying no immediate risk and no action required at this time. Monitor vendor communications for updates or official fixes.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- mitre
- Date Reserved
- 2024-08-05T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 699f6cc1b7ef31ef0b568d3f
Added to database: 02/25/2026, 21:42:25 UTC
Last enriched: 07/05/2026, 21:21:00 UTC
Last updated: 09/10/2026, 19:36:48 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.