Impact
Moquette, a lightweight Java MQTT broker, allows a client to configure a Last‑Will message for a topic to which it does not have write access. The broker publishes this message when the client disconnects unexpectedly without enforcing the write authorization or reserved‑topic checks that normally protect normal PUBLISH traffic. This defect enables any client that can connect to the broker to inject messages into restricted topics, potentially disrupting services, leaking information or modifying data that subscribers are not permitted to see.
Affected Systems
The flaw exists in all Moquette releases prior to 0.18.1. The affected product is the Moquette MQTT broker, with all versions before v0.18.1 susceptible. The vendor is moquette‑io and the product name is Moquette.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. While an EPSS score is not currently available, the lack of mitigation in earlier versions and the ability for any authenticated or unauthenticated client to set an unauthorized Last‑Will suggest a realistic attack surface. The flaw is not listed in the CISA KEV catalog, but its severity and potential impact warrant immediate attention. Attackers can exploit the weakness simply by configuring an unexpected disconnection for a client with a prohibited Last‑Will topic; no additional privileges or knowledge are required beyond initial broker access.
OpenCVE Enrichment