Impact
An authentication or authorization flaw allows a physically proximate attacker to leverage the RSA private key component on the Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera to elevate privileges. The vulnerability involves insufficient protection of the RSA private key, identified as CWE-321, and can give the attacker higher-level access to the device, potentially enabling unauthorized control or data extraction.
Affected Systems
The affected product is the Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera running firmware version 1.0. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity for privilege escalation. The EPSS score is less than 1%, reflecting a very low likelihood of exploitation in the wild. The vulnerability requires physical proximity to the device, limiting the attack surface but still posing a risk for installations in publicly accessible locations. The CVE does not appear in the CISA KEV catalog, and no publicly available fix or workaround is detailed in the supplied references.
OpenCVE Enrichment