Sencore has released firmware updates for several of its broadcast hardware platforms to address two critical vulnerabilities in the open-source SRT library. The patches resolve a buffer overflow and an encryption state machine downgrade that could potentially allow unauthorized access or remote code execution.
The discovery of high-severity flaws in the open-source SRT library highlights the inherent risks of relying on shared protocols for mission-critical IP-based media transport. For broadcasters using Sencore hardware, these patches are essential to prevent stream hijacking and unauthorized content injection on exposed endpoints. This event underscores a broader industry need for rigorous lifecycle management of embedded open-source components within proprietary broadcast stacks. As the SRT Alliance continues to refine the protocol, engineers should monitor for further library updates and prioritize the transition to version v1.5.6 to maintain infrastructure integrity.
Sencore's patch cycle reflects a broader pattern of SRT library vulnerabilities surfacing across broadcast hardware vendors. In early 2025, the SRT Alliance released version 1.5.4 of the open-source protocol library with fixes for multiple memory-safety issues, including heap-based buffer overflows that shared a similar attack surface with the flaws Sencore addressed. The Haivision SRT project, which governs the library's development, has accelerated its release cadence since 2024 as adoption in professional video transport has grown, with each point release targeting CVEs that affect embedded implementations in encoders, decoders, and gateways.
The business and standards context around SRT continues to tighten as broadcasters migrate from satellite and SDI contribution to IP-based workflows. Haivision reported in its Q2 2025 earnings that SRT-based contribution revenue grew 28% year over year, driven by sports and news organizations replacing dedicated circuits with internet transport. That growth increases the attack surface: every additional SRT endpoint deployed on public or semi-public networks becomes a potential target if running unpatched library versions. The SRT Alliance, which includes Sencore, Haivision, and more than 50 other member companies, has not yet published a formal security advisory process comparable to what IETF RFCs provide for internet protocols, leaving individual vendors to issue their own patch notifications.
Competing transport protocols used in the same broadcast contribution and distribution workflows face similar scrutiny. RIST Forum published updated security guidance in 2025 recommending that operators disable pre-shared key mode in favor of certificate-based authentication for production deployments, citing brute-force risks against short PSKs. Meanwhile, Zixi reported that its SDVP platform added hardware root-of-trust attestation for edge appliances in mid-2025, positioning verified boot as a differentiator against the class of firmware-level exploits that Sencore's patches address. For broadcast engineers evaluating Sencore hardware alongside alternatives, the key operational takeaway is that SRT, RIST, and Zixi all require active patch management programs, and the window between CVE disclosure and vendor firmware release remains the primary exposure period.
Sencore has released firmware updates to address two critical security flaws in its broadcast hardware, including a stack-based buffer overflow with a 9.1 CVSS score. These patches are essential for broadcasters to prevent remote code execution, stream hijacking, and unauthorized content injection on exposed IP-based media transport endpoints.
Affected hardware includes the Centra Gateway, MRD 7000, MRD 8000, Impulse series, SCP 2100, AFN, and VB platforms.
The update resolves a critical stack-based buffer overflow (CVE-2026-55869) and encryption state machine downgrades, which could allow remote code execution without valid credentials.
Users should upgrade to firmware version v1.5.6, which updates the embedded SRT library to resolve the identified security vulnerabilities.
Yes, interim mitigations include restricting SRT listener ports and utilizing VPN or VPC peering for secure transport.
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source