Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-11757

Опубликовано: 21 окт. 2025
Источник: nvd
EPSS Низкий

Описание

The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these messages, the attacker can obtain the credentials and key information to connect to the cameras from peer to peer.

EPSS

Процентиль: 20%
0.00063
Низкий

Дефекты

CWE-155

Связанные уязвимости

github
4 месяца назад

The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these messages, the attacker can obtain the credentials and key information to connect to the cameras from peer to peer.

EPSS

Процентиль: 20%
0.00063
Низкий

Дефекты

CWE-155