CVE-2026-26340

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized disclosure of surveillance data.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tattile:smart\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tattile:smart\+:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tattile:tolling\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tattile:tolling\+:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tattile:smart\+_speed_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tattile:smart\+_speed:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:tattile:smart\+_traffic_light_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tattile:smart\+_traffic_light:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:tattile:axle_counter_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tattile:axle_counter:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:tattile:vega53_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tattile:vega53:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:tattile:vega33_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tattile:vega33:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:tattile:vega11_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tattile:vega11:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:tattile:basic_mk2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tattile:basic_mk2:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:tattile:anpr_mobile_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tattile:anpr_mobile:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-24 20:27

Updated : 2026-02-26 17:38


NVD link : CVE-2026-26340

Mitre link : CVE-2026-26340

CVE.ORG link : CVE-2026-26340


JSON object : View

Products Affected

tattile

  • tolling\+_firmware
  • smart\+_traffic_light
  • vega33_firmware
  • smart\+_traffic_light_firmware
  • smart\+_speed_firmware
  • smart\+_speed
  • axle_counter_firmware
  • basic_mk2
  • tolling\+
  • vega11_firmware
  • anpr_mobile
  • basic_mk2_firmware
  • smart\+
  • vega53
  • vega33
  • vega11
  • axle_counter
  • vega53_firmware
  • smart\+_firmware
  • anpr_mobile_firmware
CWE
CWE-306

Missing Authentication for Critical Function