VulnerabilityAnalyzed
CVE-2025-14747
A vulnerability was found in Ningyuanda TC155 57.0.2.0.
LOW 2.1EPSS 0.71%
Does this matter?
Lower severity and a low EPSS score (0.71%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in Ningyuanda TC155 57.0.2.0. The impacted element is an unknown function of the component RTSP Service. Performing manipulation results in denial of service. The attack must originate from the local network. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.71% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-404
- Affected
- shenzhenningyuandatechnology/tc155 firmware
- Source
- cna@vuldb.com
References
- https://github.com/pwnpwnpur1n/IoT-advisories/blob/main/TC155-Unauth-Malformed-RTSP-Describe-Request.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.336520Permissions Required, VDB Entry
- https://vuldb.com/?id.336520Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.707196Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.