Junglewise Threat Intelligence

CVE-2026-37270: Trueview T18161-AF authentication bypass via hard-coded credentials

CVE-2026-37270 · Severity: info · Published 2026-07-07

Vendors: Trueview.

Executive brief

Trueview T18161-AF security cameras contain a security flaw that allows unauthorized individuals to bypass the login process. This is caused by the use of fixed, unchangeable passwords hidden within the device's software and errors in how the camera verifies user credentials. An attacker could exploit this to gain full access to the camera's video feed and settings without knowing the owner's password.

Technical details

An authentication bypass vulnerability exists in the Trueview T18161-AF security camera running firmware version 4.9.60.0. The flaw stems from two primary issues: improper validation of user-supplied passwords and the inclusion of hard-coded, recoverable credentials within the firmware image. An attacker with network access to the device can leverage these weaknesses to bypass standard authentication mechanisms. This allows for unauthorized administrative access to the camera's web interface or management services. No patch or mitigation was specified in the initial disclosure.

Affected products

  • Trueview T18161-AF Security Camera v4.9.60.0

Timeline

  • 2026-07-07: disclosed: Initial vulnerability disclosure and CVE assignment

References