CVE-2025-11757
The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these messages, the attacker can obtain the credentials and key information to connect to the cameras from peer to peer.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.30%
- CWE
- CWE-155
- Published
- 2025-10-21
- Last modified
- 2026-03-12
Affected products
- CloudEdge CloudEdge App
Weakness type
Related vulnerabilities
- CVE-2026-87016 — Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
- CVE-2026-68939 — Pyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)
- CVE-2026-73412 — Shescape: Path disclosure on Unix with Zsh
- CVE-2026-49482 — ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite
- CVE-2025-4232 — GlobalProtect: Authenticated Code Injection Through Wildcard on macOS
- CVE-2025-27515 — Laravel has a File Validation Bypass
- CVE-2025-0681 — New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbols
- CVE-2025-24376 — The kubewarden-controller AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter PolicyReport resources