DEF CON Toronto (DC416) runs a coordinated vulnerability disclosure program. Research by our community is reported to affected vendors under our disclosure policy, and CVE identifiers are requested through MITRE’s CNA of Last Resort until DC416 is authorized to assign them directly.
| Advisory | Title | Severity | CVE | Disclosed |
|---|---|---|---|---|
| DC416-2026-0001 | Fleet-wide root shell via unauthenticated MQTT command injection | Critical 10.0 | Pending | 2026-10-04 |
| DC416-2026-0002 | MQTT broker ACL wildcard inversion leaks cross-tenant config | High 7.1 | Pending | 2026-10-04 |
| DC416-2026-0003 | Unauthenticated getVipUserId account-existence oracle | Medium 6.9 | Pending | 2026-10-04 |
| DC416-2026-0004 | devmanager.do device-ID oracle and backend metadata leak | Medium 5.3 | Pending | 2026-10-04 |
| DC416-2026-0005 | Login API account-state oracle enabling email enumeration | Medium 6.9 | Pending | 2026-10-04 |
CVE identifiers for the advisories above have been requested from MITRE CNA-LR and are pending assignment; each advisory will be updated with its assigned CVE ID. Machine-readable records (CVE JSON 5.1) are linked from each advisory.
See our Vulnerability Disclosure Policy and security.txt.
Email: cve@defcontoronto.ca
Discord: discord.gg/VDy69zgfc3