CVE-2026-79390 Details
Description
Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the transmission of MQTT communications in plaintext over TCP port 1883. An unauthenticated attacker with access to the same network segment can intercept MQTT traffic and obtain sensitive device information and operational data, including device identifiers, message metadata, and control-related information.
A vulnerability in the Trueview TI8161 security camera, running firmware version 6.0.23.4, allows for information disclosure through unencrypted MQTT communications over TCP port 1883. An unauthenticated attacker on the same network segment can intercept the MQTT traffic and access sensitive device information and operational data. This includes device identifiers, message metadata, and control-related information, all transmitted in plaintext without any encryption.
Users are advised to enable MQTT over TLS to secure communications and prevent interception of message contents. The camera should also validate the MQTT broker's TLS certificate, avoiding untrusted certificates. Additionally, reusable secrets should not be transmitted in MQTT payloads, and sensitive information should be minimized.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/EmbdCDACHyd/CVE/blob/main/CVE-2026-79390/README.md | [email protected] | Technical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Trueview TI8161 | 6.0.23.4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion