CVE-2026-26340
EUVD-2026-855024.02.2026, 20:27
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized disclosure of surveillance data.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tattile | smart\+_firmware | 𝑥 ≤ 1.181.5 |
| tattile | tolling\+_firmware | 𝑥 ≤ 1.181.5 |
| tattile | smart\+_speed_firmware | 𝑥 ≤ 1.181.5 |
| tattile | smart\+_traffic_light_firmware | 𝑥 ≤ 1.181.5 |
| tattile | axle_counter_firmware | 𝑥 ≤ 1.181.5 |
| tattile | vega53_firmware | 𝑥 ≤ 1.181.5 |
| tattile | vega33_firmware | 𝑥 ≤ 1.181.5 |
| tattile | vega11_firmware | 𝑥 ≤ 1.181.5 |
| tattile | basic_mk2_firmware | 𝑥 ≤ 1.181.5 |
| tattile | anpr_mobile_firmware | 𝑥 ≤ 1.181.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration