Back to Bulletins
Author:Security Team
Published:2026-03-12

Multiple Security Issues in EMQX Component

Summary :
The EMQX component has multiple security risks such as missing device authentication and default console credentials.

CVSS (Base Score):

9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

Attack Conditions:

Attackers can directly access the EMQX service over the network, subscribe to all user messages by abusing missing device-level authentication, or log in to the console with default credentials to view information.

Risk:

This vulnerability may lead to leakage of communication data between users and devices, and attackers may obtain system messages via the console.

Impact Scope:

This issue affects the deprecated EMQX component on devices below version 3.0.0.

Remediation Steps:

The legacy EMQX component has been fully retired and stopped. Devices running versions prior to 3.0.0 must be upgraded. The current supported release is 6.0.1.
Acknowledgment

We thank Sammy Azdoufal for valuable assistance in discovering this vulnerability and coordinating responsible disclosure.