---
id: CVE-2025-14746
title: A vulnerability has been found in Ningyuanda TC155 57.0.2.0
summary: >-
  A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected
  element is an unknown function of the component RTSP Live Video Stream
  Endpoint. Such manipulation leads to improper authentication. The attack must
  be carried out…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-287
vendor: shenzhenningyuandatechnology
product: tc155_firmware
affected:
  - tc155_firmware = 57.0.2.0
published: '2025-12-16'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14746'
references:
  - url: >-
      https://github.com/pwnpwnpur1n/IoT-advisories/blob/main/TC155-Unauth-RTSP.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.336519'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.336519'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.707195'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00884
epssPercentile: 0.57876
ingestedAt: '2026-10-07T20:46:46.946Z'
---

## Overview

A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the component RTSP Live Video Stream Endpoint. Such manipulation leads to improper authentication. The attack must be carried out from within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `tc155_firmware = 57.0.2.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
