ZeroHour

CVE-2026-79390

niche

Plaintext MQTT Information Disclosure in Trueview TI8161

CVSS 3.1
7.5 high
EPSS
<1%p17
Published
()
Modified
AI analysis

Trueview TI8161 firmware 6.0.23.4 transmits its MQTT communications unencrypted in plaintext over TCP port 1883 instead of using an encrypted channel such as MQTT over TLS. An unauthenticated attacker who can reach the same network segment simply passively captures this traffic; no authentication or user interaction is required. Captured messages expose sensitive device information and operational data, including device identifiers, message metadata, and control-related information, which an attacker could use for reconnaissance or device fingerprinting; confidentiality is impacted, while integrity and availability are not. Any deployment running the TI8161 on version 6.0.23.4 with MQTT traffic on port 1883 is affected, though the attack is limited to attackers already positioned on the local network segment. No exploitation, public proof-of-concept, or KEV listing is currently known, and EPSS puts 30-day exploitation probability at only about 0.1%.

What to do: No fixed firmware version is documented in the available data, so contact Trueview for an updated release and, in the meantime, check whether the device supports MQTT over TLS (port 8883) and enable it. Restrict and segment TCP 1883 so MQTT traffic is not reachable from untrusted parts of the network, and treat any device identifiers or control details exposed on the segment as potentially recoverable by local attackers. Re-check the advisory once a patched version number is published before planning upgrades.

Affected
Trueview TI81616.0.23.4 (the only version listed; no fixed version or broader range is provided in the data)
Estimated exposure
nichelikely hundreds to low thousands of deployed units; exact install base unknown — The data provides no install counts, and Trueview is a niche IoT camera vendor with a single model named, so the estimate reflects typical small-vendor deployment volumes, with exposure further limited by the requirement that an attacker…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the transmission of MQTT communications in plaintext over TCP port 1883. An unauthenticated attacker with access to the same network segment can intercept MQTT traffic and obtain sensitive device information and operational data, including device identifiers, message metadata, and control-related information.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.