CVE-2025-9161

Severity CVSS v4.0:
HIGH
Type:
CWE-77 Command Injection
Publication date:
09/09/2025
Last modified:
20/10/2025

Description

A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, which can be used to achieve remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rockwellautomation:factorytalk_optix:*:*:*:*:*:*:*:* 1.5.0 (including) 1.6.0 (excluding)