Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modify captured MQTT messages, including security-related nonce, timestamp, and signature fields, and the device accepts the modified messages and executes the associated commands.
History

Fri, 04 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Replay-based Command Injection via MQTT in Trueview T18161 Device
Weaknesses CWE-285

Fri, 04 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modify captured MQTT messages, including security-related nonce, timestamp, and signature fields, and the device accepts the modified messages and executes the associated commands.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-09-04T00:00:00.000Z

Updated: 2026-09-04T19:56:41.996Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79389

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-04T20:17:28.133

Modified: 2026-09-08T19:39:43.673

Link: CVE-2026-79389

cve-icon Redhat

No data.