CVE-2017-10796: TP-Link NC250 Firmware

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp URL.

Affected products

  • TP-Link NC250 Firmware: up to and including 1.2.1

Published 2017-07-02. Last modified 2026-06-17.