CVE-2025-11757

The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these messages, the attacker can obtain the credentials and key information to connect to the cameras from peer to peer.
CVSS

No CVSS.

Configurations

No configuration.

History

21 Oct 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-21 18:15

Updated : 2025-10-21 19:31


NVD link : CVE-2025-11757

Mitre link : CVE-2025-11757

CVE.ORG link : CVE-2025-11757


JSON object : View

Products Affected

No product.

CWE
CWE-155

Improper Neutralization of Wildcards or Matching Symbols