CVE-2026-79389
Received Received - Intake

MQTT Message Replay and Modification in Trueview T18161 S

Vulnerability report for CVE-2026-79389, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: MITRE

Description

Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modify captured MQTT messages, including security-related nonce, timestamp, and signature fields, and the device accepts the modified messages and executes the associated commands.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trueview t18161 6.0.23.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an improper verification flaw in the MQTT command processing of Trueview T18161 S version 6.0.23.4. An attacker with network access can replay or alter captured MQTT messages, including critical security fields like nonce, timestamp, and signature. The device fails to properly verify these modified messages and executes the associated commands.

Impact Analysis

An attacker could exploit this to send unauthorized commands to the device, potentially gaining control over its functions. This might lead to data breaches, device manipulation, or disruption of services relying on the device. Physical or operational consequences depend on the device's role in the system.

Compliance Impact

This vulnerability could compromise data integrity and confidentiality, violating requirements for secure communication and authentication in standards like GDPR and HIPAA. Non-compliance may result if the device is used in environments requiring these protections.

Mitigation Strategies

Isolate the Trueview T18161 device from untrusted networks. Update to the latest firmware if available. Monitor MQTT traffic for unexpected command executions or modified messages. Restrict network access to the device using firewalls or VLANs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79389. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart