High severity8.8NVD Advisory· Published Sep 9, 2025· Updated Jun 17, 2026
CVE-2025-9161
CVE-2025-9161
Description
A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, which can be used to achieve remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:rockwellautomation:factorytalk_optix:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:rockwellautomation:factorytalk_optix:*:*:*:*:*:*:*:*range: >=1.5.0,<1.6.0
- (no CPE)
- Range: All Versions 1.5.0 - 1.5.7
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.