PT-2026-98302 · Isteamx · Isteamx
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
iSteamX mobile application versions prior to 9/18/2026
Description
The AWS policy of the application allows authenticated users to access wildcard MQTT topics. This flaw enables an attacker to expose device data from other users and control their connected devices by starting or stopping them. Potential impacts include the exposure of user profile information and physical risks, such as scalding, resulting from unintended device activation.
Recommendations
Update the iSteamX mobile application to the version released on or after 9/18/2026.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Isteamx