Description
No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or subscribe operations.
Published: 2026-09-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Trueview 6.0.23.4 allows attackers to connect to the MQTT broker on TCP port 1883 without authentication and to publish or subscribe to any topic. This lack of identity verification enables unauthorized disclosure or manipulation of MQTT messages, potentially compromising confidentiality, integrity, and availability of data transmitted through the broker. The weakness involves improper access control, specifically missing authentication requirements for a critical communication service.

Affected Systems

Trueview Trueview 6.0.23.4, which exposes an MQTT broker listening on TCP port 1883. The affected system is any component running this version of the Trueview software.

Risk and Exploitability

The vulnerability has no EPSS score and is not listed in CISA KEV, but the attack surface is large: any remote host with network connectivity to the MQTT port can exploit it. Because authentication is entirely absent, exploitation requires only the ability to open a TCP connection, making it highly feasible. The lack of mitigation information from the vendor indicates that a patch or update is essential to reduce this risk.

Generated by OpenCVE AI on September 4, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Trueview to a version that requires authentication for MQTT access
  • Restrict outbound/inbound access to TCP port 1883 via firewall or network segmentation
  • Configure the MQTT broker to enforce authentication and TLS encryption
  • Monitor MQTT traffic for unauthorized publish or subscribe activity

Generated by OpenCVE AI on September 4, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthorized MQTT Access in Trueview 6.0.23.4
Weaknesses CWE-284

Fri, 04 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or subscribe operations.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-04T19:59:28.308Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79391

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T20:17:28.363

Modified: 2026-09-04T20:17:28.363

Link: CVE-2026-79391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T22:15:06Z

Weaknesses