logo

IoT’s Cloud Risk on Display with Flaws in Fuze Collaboration Platform

ID: a53c1ddd-7889-542b-898a-f2d553e5cbea

STIX ID: report--a53c1ddd-7889-542b-898a-f2d553e5cbea

Feed Name: Security Ledger

Threat Score
50/100

Date Published: 2017-08-23

Date Updated: 2026-05-05

Author: Paul Roberts

...
...

Rapid7 disclosed flaws in Fuze’s web-based handset administration portal that allowed attackers to enumerate device-specific administrative URLs (derived from MAC addresses) and obtain phone numbers, email addresses, parent account names and admin links. The issues were compounded by use of HTTP (no HTTPS) and lack of rate limiting for admin logins; Fuze deployed rate limiting to mitigate the issue and reported no known exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.