Impact
Trueview TI8161 firmware 6.0.23.4 transmits MQTT traffic in clear text over TCP port 1883. The lack of encryption allows an unauthenticated attacker who can reach the same local network segment to capture device identifiers, message metadata, and control‑related information. This results in a confidentiality compromise that exposes sensitive operational data. The description does not indicate any additional impact such as system modification or privilege escalation.
Affected Systems
The Trueview TI8161 device running firmware version 6.0.23.4 is affected. No other vendors or product variants are listed in the advisory.
Risk and Exploitability
The exploit requires only local network connectivity to the MQTT broker on port 1883. No authentication or special privileges are needed; passive packet capture is sufficient. The CVSS score of 7.5 indicates a high severity, while the EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, so no known active exploit is documented. These factors together result in a moderate risk for environments that expose the broker to local networks, owing to potential data exposure.
OpenCVE Enrichment