An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://cds.thalesgroup.com/en |
|
History
Thu, 08 Jan 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Efacec
Efacec qc 120 Efacec qc 60 Efacec qc 90 |
|
| Vendors & Products |
Efacec
Efacec qc 120 Efacec qc 60 Efacec qc 90 |
Wed, 07 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications | |
| Title | FRAIL SECURITY IN MQTT PROTOCOL ALLOWS AN ATTACKER MODIFY CRITICAL PARAMETERS | |
| Weaknesses | CWE-1366 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: S21sec
Published:
Updated: 2026-01-07T16:59:20.174Z
Reserved: 2026-01-07T14:01:04.828Z
Link: CVE-2026-22535
Updated: 2026-01-07T16:59:16.364Z
Status : Awaiting Analysis
Published: 2026-01-07T17:16:03.580
Modified: 2026-01-08T18:08:54.147
Link: CVE-2026-22535
No data.
OpenCVE Enrichment
Updated: 2026-01-08T09:48:30Z