Description
LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions.
Problem types
Product status
Any version before 2026.04.22
Credits
Younghyo Cho @ CIS Lab., Seoultech
VulnCheck
References
gist.github.com/yhcho0405/ee9b67a96808ef19f22e8a4ee88c795f
download.live555.com/
www.vulncheck.com/...-authorization-bypass-via-session-token