Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-464p-mh7x-6549

Опубликовано: 21 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these messages, the attacker can obtain the credentials and key information to connect to the cameras from peer to peer.

The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these messages, the attacker can obtain the credentials and key information to connect to the cameras from peer to peer.

EPSS

Процентиль: 20%
0.00063
Низкий

8.7 High

CVSS4

Дефекты

CWE-155

Связанные уязвимости

nvd
4 месяца назад

The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these messages, the attacker can obtain the credentials and key information to connect to the cameras from peer to peer.

EPSS

Процентиль: 20%
0.00063
Низкий

8.7 High

CVSS4

Дефекты

CWE-155