CVE-2025-0681: New Rock Technologies MX8G Voip Gateway
Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.
The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service communications.
Affected products
- New Rock Technologies MX8G Voip Gateway: any version
- New Rock Technologies NRP1302/P Desktop IP Phone: any version
- New Rock Technologies OM500 IP-Pbx: any version
Published 2025-01-30. Last modified 2026-06-17.