←Back to Bulletins
Multiple Security Issues in EMQX Component
Summary :
The EMQX component has multiple security risks such as missing device authentication and default console credentials.
CVSS (Base Score):
9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Attack Conditions:
Attackers can directly access the EMQX service over the network, subscribe to all user messages by abusing missing device-level authentication, or log in to the console with default credentials to view information.
Risk:
This vulnerability may lead to leakage of communication data between users and devices, and attackers may obtain system messages via the console.
Impact Scope:
This issue affects the deprecated EMQX component on devices below version 3.0.0.
Remediation Steps:
The legacy EMQX component has been fully retired and stopped.
Devices running versions prior to 3.0.0 must be upgraded. The current supported release is 6.0.1.