Impact
Trueview Security camera T18161‑AF firmware version 4.9.60.0 validates supplied credentials against hard‑coded values and performs only superficial password checks. This flaw allows an attacker who knows or guesses a hard‑coded credential to gain full control of the device without possessing the legitimate user password. The vulnerability is a classic authentication bypass (CWE‑287) and is aggravated by the presence of hard‑coded credentials (CWE‑798).
Affected Systems
The only product explicitly identified in the CVE record is a Trueview Security camera model T18161‑AF running firmware 4.9.60.0. No other vendors, product models, or firmware revisions are listed, indicating that impacts are known only for this specific firmware version unless later releases are updated.
Risk and Exploitability
The CVSS score of 9.8 marks this vulnerability as critical. An EPSS score of less than 1 % suggests that exploitation events are currently rare, and the vulnerability is The: an attacker can reach the camera’s management interface or any exposed network API that performs the flawed credential check over the network. Successful exploitation would give the attacker unrestricted control over the camera, enabling configuration changes, firmware updates, or data exfiltration.
OpenCVE Enrichment