CVE-2026-79391 Details
Description
No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or subscribe operations.
A vulnerability exists in the Trueview Security Camera model T18161 S running firmware version 6.0.23.4, where the MQTT service does not require client authentication. The MQTT broker accepts connections on TCP port 1883 without authentication, allowing remote attackers with network access to establish MQTT sessions and perform unauthorized publish or subscribe operations. This lack of authentication weakens the access control of the MQTT service, potentially allowing unauthorized clients to interact with topics intended for legitimate devices or services.
It is recommended to disable anonymous MQTT connections, implement strong client authentication, consider certificate-based authentication, and apply topic-level authorization to restrict client access to only necessary MQTT topics and operations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/EmbdCDACHyd/CVE/blob/main/CVE-2026-79391/README.md | [email protected] | ExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Trueview T18161 S | 6.0.23.4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion