Back to Bulletins
Author:Security Team
Published:2026-03-02 15:52

Multiple Security Issues in EMQX Component

Summary :
The EMQX component has multiple security risks such as missing device authentication and default console credentials.

CVSS (Base Score):

9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

Attack Conditions:

Attackers can directly access the EMQX service over the network, subscribe to all user messages by abusing missing device-level authentication, or log in to the console with default credentials to view information.

Risk:

This vulnerability may lead to leakage of communication data between users and devices, and attackers may obtain system messages via the console.

Impact Scope:

This issue affects the deprecated EMQX component on devices below version 3.0.0.

Remediation Steps:

The legacy EMQX component has been fully retired and stopped. Devices running versions prior to 3.0.0 must be upgraded. The current supported release is 6.0.1.