Description
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized disclosure of surveillance data.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
Any version
Any version
Any version
Any version
Any version
Any version
Any version
Any version
Any version
Any version
Credits
Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5978.php
www.tattile.com/
www.vulncheck.com/...-unauthenticated-rtsp-stream-disclosure