Unrated severityNVD Advisory· Published Sep 9, 2025· Updated Sep 9, 2025
Rockwell Automation FactoryTalk Optix Remote Code Execution Vulnerability
CVE-2025-9161
Description
A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, which can be used to achieve remote code execution.
Affected products
1- Rockwell Automation/FactoryTalk Optixv5Range: All Versions 1.5.0 - 1.5.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.