CVE-2026-51977

9.1

Trueview · T18061 WiFi 3MP Robot Pan-Tilt Security Camera

A privilege escalation vulnerability in Trueview T18061 WiFi 3MP security cameras allows physically proximate attackers to compromise the device via an exposed RSA private key.

Executive summary

The Trueview T18061 WiFi 3MP security camera is vulnerable to privilege escalation due to an exposed RSA private key, allowing unauthorized device impersonation.

Vulnerability

The device suffers from improper protection of its RSA private key component. This allows a physically proximate, unauthenticated attacker to escalate privileges and perform device impersonation, undermining the security model of the camera.

Business impact

With a CVSS score of 9.1, this vulnerability is critical. An attacker capable of impersonating security hardware can gain unauthorized access to video feeds or use the device as a foothold to attack the broader network. This presents a severe risk to both physical security and network integrity, potentially leading to widespread unauthorized access.

Remediation

Immediate Action: Consult the vendor for security firmware updates to address the private key exposure. If no update is available, consider isolating these devices from critical network segments.

Proactive Monitoring: Monitor network traffic for anomalous authentication attempts or unusual communication patterns originating from the security camera devices.

Compensating Controls: Implement physical access controls to prevent unauthorized individuals from reaching the device, and place cameras on a dedicated, firewalled VLAN to restrict potential network-based exploitation.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept is available via the referenced GitHub repository.

Analyst recommendation

Due to the critical severity and the existence of a public proof-of-concept, immediate isolation of affected hardware is recommended. Administrators should prioritize replacing or updating any devices identified as running the vulnerable firmware to prevent unauthorized access.