Impact
Sipeed PicoClaw devices up to version 0.2.9 contain a flaw in the MQTT Channel Handler where manipulation of the client_id argument can lead to incorrect authorization decisions. This weakness allows an attacker to impersonate a legitimate client or gain unauthorized access to MQTT topics. The flaw is linked to CWE-285 (Authorization) and CWE-863 (Role‑Based Access Control).
Affected Systems
The affected product is Sipeed PicoClaw, specifically versions up to 0.2.9. No fixed release is listed in the current data, so any deployment running a version prior to 0.2.9 is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The description notes that the attack can be carried out remotely by sending a crafted client_id to the MQTT channel. No additional exploitation conditions are stated, so network exposure of the MQTT service increases risk.
OpenCVE Enrichment