Executive brief
The Trueview T18061 WiFi security camera contains a hardcoded RSA private key embedded in its firmware that is used to authenticate communications with cloud services. An attacker with physical access to the device can extract the firmware, obtain the private key, and use it to impersonate the device and forge authentication signatures, potentially gaining unauthorized access to cloud accounts, video streams, and device settings.
Technical details
The vulnerability is a hardcoded cryptographic key issue affecting firmware version 1.0 of the Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera. The RSA private key is embedded at /usr/local/rsa_private_key.pem within the firmware image and is used by the anyka_ipc binary to generate SHA-256-based RSA signatures for cloud API authentication via WolfSSL. An attacker with physical access can extract the firmware image from the device, unpack the filesystem, and recover the shared private key. With this key, an attacker can forge valid authentication signatures, bypass device-to-cloud authentication, and potentially escalate privileges on cloud accounts linked to the camera. No patch information is currently available; remediation requires firmware update with a device-unique key or certificate-based authentication.
Affected products
- Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera 1.0
Timeline
- 2026-08-17: disclosed