Description
An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An exploitation path exists in the Trueview T18061 WiFi 3MP Robot Pan‑Tilt Security Camera that allows a physically proximate attacker to leverage an exposed RSA private key component to elevate privileges on the device. The vulnerability permits the attacker to gain higher‑level access, potentially controlling camera settings, capturing data, or using the device as a foothold for further network attacks. The weakness stems from insufficient protection or validation of the private key, enabling privilege escalation without any remote input from the network.

Affected Systems

The affected product is the Trueview T18061 WiFi 3MP Robot Pan‑Tilt Security Camera running firmware version 1.0. No other vendor or product versions are reported as affected at this time.

Risk and Exploitability

Exploitability requires close physical proximity to the camera, which limits the attack surface but still poses a significant risk to owners situating the device in accessible locations. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, however the lack of a publicly released fix means that operators must rely on manual mitigations. An attacker with access could immediately gain privileged control, underscoring a high-security impact for exposed installations.

Generated by OpenCVE AI on August 18, 2026 at 00:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact Trueview to obtain and apply any vendor‑released firmware update that secures the RSA private key component.
  • If a firmware fix is not yet available, reconfigure the device or disable any settings that expose the private key, or replace the camera with a model that does not store keys locally.
  • Physically secure the camera and restrict proximity to authorized personnel only.

Generated by OpenCVE AI on August 18, 2026 at 00:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via RSA Private Key on Trueview T18061 Camera
Weaknesses CWE-732
CWE-862

Mon, 17 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T21:59:26.469Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51977

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T22:17:14.487

Modified: 2026-08-17T22:17:14.487

Link: CVE-2026-51977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:15:03Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource

  • CWE-862

    Missing Authorization