A critical vulnerability was identified in CloudEdge online cameras and the associated app, allowing attackers to exploit improper neutralization of wildcards or matching symbols in MQTT topic inputs. The vulnerability, tracked as CVE-2025-11757, arises because the CloudEdge Cloud does not properly sanitize MQTT topic input, enabling an attacker to subscribe to a wildcard MQTT topic and receive messages intended for other users. Through this method, an attacker can intercept sensitive information, including credentials and key data necessary to connect to peer-to-peer cameras. The vulnerability is remotely exploitable and has been assigned a CVSS v4 base score of 8.7, indicating high severity. The affected product includes at least CloudEdge App version 4.4.2, with the potential for other versions or products to be impacted, though a comprehensive list of affected products is not yet available. The exploitation of this flaw could allow unauthorized access to live video feeds and camera controls, posing significant privacy and security risks to users worldwide. The vulnerability was reported by a researcher known as Ph4ng0t and disclosed through CISA and CVE advisories. CloudEdge and its parent company, Meari Technologies, have not responded to CISA's attempts at coordinated disclosure, and as of the latest advisories, no official mitigation or patch has been provided by the vendor. The vulnerability affects commercial facilities and is deployed globally, with the company headquartered in China. The lack of input sanitization in the MQTT protocol implementation is the core technical issue, making it possible for attackers to eavesdrop on communications and potentially compromise a large number of devices. The risk evaluation highlights that attackers could gain access to sensitive information, which could be used for further attacks or unauthorized surveillance. The advisories recommend that users remain vigilant and monitor for updates, but without vendor cooperation, users may need to consider additional network segmentation or device isolation as interim protective measures. The incident underscores the importance of secure MQTT implementation and the risks associated with hard-coded credentials and poor input validation in IoT devices. The vulnerability has drawn attention from both government and independent security researchers due to its potential impact on privacy and security. Organizations using CloudEdge products are advised to assess their exposure and consider alternative security controls until a vendor fix is available. The case also highlights ongoing challenges in coordinated vulnerability disclosure, especially with vendors that are unresponsive to security advisories.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
In the same 2025-10-21 advisory, CISA reported that CloudEdge and parent company Meari Technologies did not respond to coordination attempts. CISA also said it was not aware of any public exploitation specifically targeting the vulnerability at the time of publication.
On 2025-10-21, CISA published ICS Advisory ICSA-25-294-05 warning that CloudEdge App version 4.4.2 and associated CloudEdge Online Cameras are affected by CVE-2025-11757, an improper neutralization of MQTT wildcards vulnerability. The flaw could let an unauthenticated attacker subscribe to broad MQTT topics, exposing credentials and key material that could enable access to live video feeds and camera control.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.