CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-0681: New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbols

6.9 CVSS

Description

The Cloud MQTT service of the affected products supports wildcard topic
subscription which could allow an attacker to obtain sensitive
information from tapping the service communications.

Classification

CVE ID: CVE-2025-0681

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.9

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products

Vendor: New Rock Technologies

Product: OM500 IP-PBX

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.77% (scored less or equal to compared to others)

EPSS Date: 2025-02-28 (when was this score calculated)

References

https://www.cisa.gov/news-events/ics-advisories/icsa-25-030-02
https://www.newrocktech.com/ContactUs/index.html

Timeline