CVE-2026-79390

Trueview · TI8161

The Trueview TI8161 device transmits MQTT communications in plaintext, allowing unauthenticated attackers on the same network segment to intercept sensitive operational data.

Executive summary

The Trueview TI8161 camera is vulnerable to plaintext information disclosure over MQTT, posing a significant risk of sensitive data exposure to unauthenticated local attackers.

Vulnerability

This is an information disclosure vulnerability where MQTT traffic is transmitted without encryption over TCP port 1883. An unauthenticated attacker positioned on the local network segment can sniff this traffic to capture device identifiers, metadata, and control information.

Business impact

Successful exploitation allows an unauthorized party to gain visibility into operational data and device-specific metadata. Given the CVSS score of 7.5, this high-severity vulnerability could lead to the compromise of proprietary information or facilitate further reconnaissance for more complex attacks against the local infrastructure.

Remediation

Immediate Action: Restrict network access to the affected device to trusted management VLANs and disable external access to TCP port 1883 until a secure firmware update is released by the manufacturer.

Proactive Monitoring: Monitor network traffic for unusual activity on port 1883 and implement intrusion detection systems to alert on unauthorized attempts to access MQTT broker communications.

Compensating Controls: Deploy a network-based firewall to isolate the device from untrusted segments and utilize a VPN or encrypted tunnel to encapsulate any necessary remote communication.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Because this vulnerability allows for the passive interception of sensitive operational data without authentication, it represents a significant security oversight. Organizations using the Trueview TI8161 should immediately segment these devices from public or untrusted networks and contact the vendor for information regarding a secure firmware update to enable encrypted MQTT communication.

More Trueview CVEs

History

CVE Brief tracked this CVE 5 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1)
  4. Analyst report written

Sources