Description
An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component
Published: 2026-08-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication or authorization flaw allows a physically proximate attacker to leverage the RSA private key component on the Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera to elevate privileges. The vulnerability involves insufficient protection of the RSA private key, identified as CWE-321, and can give the attacker higher-level access to the device, potentially enabling unauthorized control or data extraction.

Affected Systems

The affected product is the Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera running firmware version 1.0. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity for privilege escalation. The EPSS score is less than 1%, reflecting a very low likelihood of exploitation in the wild. The vulnerability requires physical proximity to the device, limiting the attack surface but still posing a risk for installations in publicly accessible locations. The CVE does not appear in the CISA KEV catalog, and no publicly available fix or workaround is detailed in the supplied references.

Generated by OpenCVE AI on August 18, 2026 at 20:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact Trueview to obtain any firmware update that addresses the RSA private key protection flaw.
  • Secure the camera physically to restrict unauthorized proximity, such as placing it in a locked enclosure.
  • If a vendor update is not yet available, consider replacing the device with a model that does not rely on locally stored RSA key material.

Generated by OpenCVE AI on August 18, 2026 at 20:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Exposed RSA Private Key on Trueview T18061 Camera

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via RSA Private Key on Trueview T18061 Camera
Weaknesses CWE-732
CWE-862

Tue, 18 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-321
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via RSA Private Key on Trueview T18061 Camera
Weaknesses CWE-732
CWE-862

Mon, 17 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-18T12:26:09.783Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51977

cve-icon Vulnrichment

Updated: 2026-08-18T12:23:16.966Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T22:17:14.487

Modified: 2026-08-31T20:12:02.273

Link: CVE-2026-51977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T20:30:17Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key