CloudEdge Cloud Improper Input Sanitization Vulnerability in MQTT Topic Handling

Vulnerability

A vulnerability exists in the CloudEdge Cloud service, specifically in the CloudEdge App version 4.4.2, due to improper sanitization of MQTT topic inputs. This flaw allows attackers to exploit MQTT wildcards to intercept messages intended for other users. By subscribing to a manipulated MQTT topic, an attacker can access messages containing sensitive information, such as credentials and keys, needed to connect to cameras in a peer-to-peer network.

Impact

Exploitation of this vulnerability could lead to unauthorized access to live video feeds and control over the affected cameras.

Remediation

CloudEdge users are advised to contact CloudEdge or Meari Technologies and keep their systems updated. CISA recommends minimizing network exposure for control system devices, using firewalls to isolate control system networks from business networks, and employing secure remote access methods like VPNs. Organizations should also follow CISA's recommended practices for ICS cybersecurity.

Added: Oct 21, 2025, 6:19 PM
Updated: Oct 21, 2025, 7:42 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
0.7
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.