CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2025-11757: CloudEdge App 4.4.2

CVE-2025-11757. EPSS 0.00322 (percentile 0.23104), scored 2026-10-06.

Affected technology

CloudEdge App · 4.4.2
CloudEdge

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

An attacker could leverage the MQTT wildcard to receive all the messages that should be delivered to other users by subscribing to the a MQTT topic. Vendor/CNA’s CVSS 4.0 assessment (base score 8.7/10) rates confidentiality impact as high; integrity and availability impact as none.

Published

CWE
CWE-155
CCR priority
0.1 /100 (P5)
EPSS
0.00322 · percentile 0.23205 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-11757.html