在2026年9月18日之前,iSteamX移动应用程序的AWS权限策略可能向已认证用户授予对通配符MQTT主题(wildcard MQTT topics)的访问权限。这种权限漏洞可能导致其他用户的设备数据被暴露,并允许攻击者启动或停止其他已连接用户控制下的设备。该问题存在用户个人资料信息泄露的风险,同时由于设备可能被意外激活,还可能导致烫伤等人身伤害。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MrSteam | iSteamX application | v1.3.42 (build 44) |
affected |
| MrSteam | iSteamX Hub | v4.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MrSteam | iSteamX application | v1.3.42 (build 44) | - |
|
| MrSteam | iSteamX Hub | v4.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet