The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these messages, the attacker can obtain the credentials and key information to connect to the cameras from peer to peer.
History

Tue, 21 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Oct 2025 17:30:00 +0000

Type Values Removed Values Added
Description The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these messages, the attacker can obtain the credentials and key information to connect to the cameras from peer to peer.
Title Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and App
Weaknesses CWE-155
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-10-21T18:29:00.590Z

Reserved: 2025-10-14T18:46:17.797Z

Link: CVE-2025-11757

cve-icon Vulnrichment

Updated: 2025-10-21T18:28:57.418Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-21T18:15:35.973

Modified: 2025-10-21T19:31:25.450

Link: CVE-2025-11757

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.