Isteamx · Isteamx · CVE-2026-95699
**Name of the Vulnerable Software and Affected Versions**
iSteamX mobile application versions prior to 9/18/2026
**Description**
The AWS policy of the application allows authenticated users to access wildcard MQTT topics. This flaw enables an attacker to expose device data from other users and control their connected devices by starting or stopping them. Potential impacts include the exposure of user profile information and physical risks, such as scalding, resulting from unintended device activation.
**Recommendations**
Update the iSteamX mobile application to the version released on or after 9/18/2026.