CVE-2025-11757None▾ SunlitThe CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these mess…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these messages, the attacker can obtain the credentials and key information to connect to the cameras from peer to peer.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85724Critical· 9.6Moquette is a lightweight Java MQTT broker
CVE-2026-68939NonePyenv provides simple Python version management
CVE-2026-87016High· 8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-73412NoneShescape is a simple shell escape library for JavaScript
GHSA-6v4m-fw66-8r4xMediumShescape: Path disclosure on Unix with Zsh