CVE-2025-0681: New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbols
Published Jan 30, 2025
·Updated
The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service communications.
Affected Software
1 affected component
New Rock Technologies Cloud Connected Devices
Event History
Jan 30, 2025
CVE Published
via MITRE·06:53 PM
Data Sourced
via MITRE·06:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-0681?
CVE-2025-0681 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2025-0681?
To mitigate CVE-2025-0681, disable wildcard topic subscriptions in the Cloud MQTT service configuration.
3
What products are affected by CVE-2025-0681?
CVE-2025-0681 affects New Rock Technologies Cloud Connected Devices that utilize the Cloud MQTT service.
4
What type of information could be exposed by CVE-2025-0681?
CVE-2025-0681 allows an attacker to potentially retrieve sensitive information that is transmitted over the MQTT service.
5
Can CVE-2025-0681 be exploited remotely?
Yes, CVE-2025-0681 can be exploited remotely if the attacker has access to the MQTT service.