{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-22535",
        "assignerOrgId": "50b5080a-775f-442e-83b5-926b5ca517b6",
        "state": "PUBLISHED",
        "assignerShortName": "S21sec",
        "dateReserved": "2026-01-07T14:01:04.828Z",
        "datePublished": "2026-01-07T16:37:18.042Z",
        "dateUpdated": "2026-01-07T16:59:20.174Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "QC 60/90/120",
                    "vendor": "EFACEC",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "8"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Aarón Flecha Menéndez"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Iván Alonso Álvarez"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Víctor Bello Cuevas"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications"
                        }
                    ],
                    "value": "An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications"
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-117",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-117 Interception"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "attackComplexity": "HIGH",
                        "attackRequirements": "NONE",
                        "attackVector": "ADJACENT",
                        "baseScore": 8.9,
                        "baseSeverity": "HIGH",
                        "exploitMaturity": "NOT_DEFINED",
                        "privilegesRequired": "LOW",
                        "providerUrgency": "NOT_DEFINED",
                        "subAvailabilityImpact": "HIGH",
                        "subConfidentialityImpact": "HIGH",
                        "subIntegrityImpact": "HIGH",
                        "userInteraction": "NONE",
                        "valueDensity": "NOT_DEFINED",
                        "vectorString": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                        "version": "4.0",
                        "vulnAvailabilityImpact": "HIGH",
                        "vulnConfidentialityImpact": "HIGH",
                        "vulnIntegrityImpact": "HIGH",
                        "vulnerabilityResponseEffort": "NOT_DEFINED"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-1366",
                            "description": "CWE-1366: Frail Security in Protocols",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "50b5080a-775f-442e-83b5-926b5ca517b6",
                "shortName": "S21sec",
                "dateUpdated": "2026-01-07T16:37:18.042Z"
            },
            "references": [
                {
                    "url": "https://cds.thalesgroup.com/en"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "tags": [
                "x_MQTT",
                "x_ICS",
                "x_Charger"
            ],
            "title": "FRAIL SECURITY IN MQTT PROTOCOL ALLOWS AN ATTACKER MODIFY CRITICAL PARAMETERS",
            "x_generator": {
                "engine": "Vulnogram 0.5.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-01-07T16:59:09.698551Z",
                                "id": "CVE-2026-22535",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-01-07T16:59:20.174Z"
                }
            }
        ]
    }
}