CVE-2025-0681
New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbols
The Cloud MQTT service of the affected products supports wildcard topic
subscription which could allow an attacker to obtain sensitive
information from tapping the service communications.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
New Rock Technologies · MX8G VoIP GatewayNew Rock Technologies · NRP1302/P Desktop IP PhoneNew Rock Technologies · OM500 IP-PBXWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →