Description
Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.
Published: 2026-07-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Trueview Security camera T18161‑AF firmware version 4.9.60.0 validates supplied credentials against hard‑coded values and performs only superficial password checks. This flaw allows an attacker who knows or guesses a hard‑coded credential to gain full control of the device without possessing the legitimate user password. The vulnerability is a classic authentication bypass (CWE‑287) and is aggravated by the presence of hard‑coded credentials (CWE‑798).

Affected Systems

The only product explicitly identified in the CVE record is a Trueview Security camera model T18161‑AF running firmware 4.9.60.0. No other vendors, product models, or firmware revisions are listed, indicating that impacts are known only for this specific firmware version unless later releases are updated.

Risk and Exploitability

The CVSS score of 9.8 marks this vulnerability as critical. An EPSS score of less than 1 % suggests that exploitation events are currently rare, and the vulnerability is The: an attacker can reach the camera’s management interface or any exposed network API that performs the flawed credential check over the network. Successful exploitation would give the attacker unrestricted control over the camera, enabling configuration changes, firmware updates, or data exfiltration.

Generated by OpenCVE AI on July 26, 2026 at 19:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the camera firmware to the latest version that removes hard‑coded credentials and implements proper authentication logic.
  • If an immediate firmware update is not available, isolate the camera from the general network, enforce strict firewall rules, and restrict management‑interface access to trusted IP addresses or a VPN tunnel to limit exposure.
  • Continuously monitor logs for failed or successful authentication attempts and enable any available intrusion detection or security monitoring tools to detect and respond to potential compromise.

Generated by OpenCVE AI on July 26, 2026 at 19:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Hard‑Coded Credentials in Trueview Security Camera Firmware

Fri, 24 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Authentication bypass via hard‑coded credentials in Trueview Security camera firmware

Tue, 21 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Authentication bypass via hard‑coded credentials in Trueview Security camera firmware

Fri, 17 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Trueview Security Camera Firmware

Wed, 15 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Trueview Security Camera Firmware

Tue, 14 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Hard‑Coded Credentials in Trueview Security Camera Firmware

Mon, 13 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Hard‑Coded Credentials in Trueview Security Camera Firmware

Sun, 12 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Hard‑Coded Credentials in Trueview Security Camera Firmware

Sat, 11 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Hard‑Coded Credentials in Trueview Security Camera Firmware

Sat, 11 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass Vulnerability in Trueview T18161‑AF Security Camera Firmware 4.9.60.0

Fri, 10 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass Vulnerability in Trueview T18161‑AF Security Camera Firmware 4.9.60.0

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-798
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass Due to Improper Password Validation and Hard-Coded Credentials in Trueview Security Camera T18161-AF v4.9.60.0
Weaknesses CWE-284
CWE-798

Thu, 09 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
References

Wed, 08 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass Due to Improper Password Validation and Hard-Coded Credentials in Trueview Security Camera T18161-AF v4.9.60.0
Weaknesses CWE-284
CWE-798

Tue, 07 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-09T14:37:59.925Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-37270

cve-icon Vulnrichment

Updated: 2026-07-09T14:37:53.988Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:00:04Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-798

    Use of Hard-coded Credentials