---
id: CVE-2025-11757
title: >-
  The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow
  an attacker to leverage the MQTT wildcard to receive all the messages that
  should be delivered to other users by subscribing to the a MQTT topic
summary: >-
  The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow
  an attacker to leverage the MQTT wildcard to receive all the messages that
  should be delivered to other users by subscribing to the a MQTT topic. In
  these mess…
severity: none
cwe:
  - CWE-155
published: '2025-10-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11757'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-294-05'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00322
epssPercentile: 0.23186
ingestedAt: '2026-10-08T11:31:27.457Z'
---

## Overview

The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these messages, the attacker can obtain the credentials and key information to connect to the cameras from peer to peer.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
