CVE-2025-11757 - CVE House
Back to Database
Status published High CVE-2025-11757

Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and App

Vulnerability Description

The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. In these messages, the attacker can obtain the credentials and key information to connect to the cameras from peer to peer.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11757

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Ph4ng0t reported this vulnerability to CISA.

Affected Vendor

Affected Software

CloudEdge App
Vulnerable Versions:
4.4.2

Timeline

Official Publish: October 21st, 2025
Last Modified: October 21st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.