ZeroHour

CVE-2026-79389

niche

MQTT Command Replay via Improper Signature Verification in Trueview T18161 S 6.0.23.4

CVSS 3.1
7.4 high
EPSS
<1%p4
Published
()
Modified
AI analysis

Trueview T18161 S devices running version 6.0.23.4 improperly verify MQTT command messages, so the nonce, timestamp, and signature fields that should authenticate those commands are not correctly checked (CWE-347). An attacker with network access who can capture MQTT traffic can replay or modify these messages, and the device will accept the tampered messages and execute the associated commands without any credentials or user interaction. This yields high confidentiality and integrity impact (CVSS 3.1: 7.4, attack complexity high because traffic capture is required), though availability is unaffected. Only this specific model and firmware version are confirmed affected. No public proof of concept exists, the flaw is not in CISA's KEV catalog, and EPSS is very low (0.1%, 4th percentile), so no exploitation has been observed.

What to do: Contact Trueview for a firmware version newer than 6.0.23.4 and apply it as soon as one is available. Until patched, remove the device from direct internet exposure, place it on an isolated VLAN with strict firewall rules limiting which hosts can reach its MQTT traffic, and disable any cloud/remote MQTT-based feature that is not required. Review device logs and network traffic for unexpected commands or configuration changes.

Affected
Trueview T18161 S
Estimated exposure
nichelikely low thousands of devices at most (single model/firmware from a small CCTV vendor; no public exposure data) — Estimated from the affected product being one specific model and firmware from a niche CCTV brand, with no public active-install counts or internet-scan figures available.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modify captured MQTT messages, including security-related nonce, timestamp, and signature fields, and the device accepts the modified messages and executes the associated commands.

Weakness
CWE-347
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.