Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-95699— MrSteam iSteamX Improper Isolation or Compartmentalization

Quick assessment

Affected
MrSteam iSteamX application
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在2026年9月18日之前,iSteamX移动应用程序的AWS权限策略可能向已认证用户授予对通配符MQTT主题(wildcard MQTT topics)的访问权限。这种权限漏洞可能导致其他用户的设备数据被暴露,并允许攻击者启动或停止其他已连接用户控制下的设备。该问题存在用户个人资料信息泄露的风险,同时由于设备可能被意外激活,还可能导致烫伤等人身伤害。

CVSS 9.6 · Critical EPSS 0.30% · P20

Affected Version Matrix 2

VendorProduct Version RangeStatus
MrSteam iSteamX application v1.3.42 (build 44) affected
MrSteam iSteamX Hub v4.2.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-95699

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MrSteam iSteamX Improper Isolation or Compartmentalization
Source: CVE Program / CVE List V5
Vulnerability Description
Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的划分
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MrSteam iSteamX application v1.3.42 (build 44) -
MrSteam iSteamX Hub v4.2.1 -

II. Public POCs for CVE-2026-95699

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-95699

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-95699 (1)

Other References for CVE-2026-95699 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-95699

No comments yet


Leave a comment