CVE-2026-79391
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or subscribe operations.
Published 2026-09-04. Last modified 2026-09-09.