VYPR
Unrated severityNVD Advisory· Published Sep 9, 2025· Updated Sep 9, 2025

Rockwell Automation FactoryTalk Optix Remote Code Execution Vulnerability

CVE-2025-9161

Description

A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, which can be used to achieve remote code execution.

Affected products

1
  • Rockwell Automation/FactoryTalk Optixv5
    Range: All Versions 1.5.0 - 1.5.7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.