Back to Database
Status published
High
CVE-2025-9161
Rockwell Automation FactoryTalk Optix Remote Code Execution Vulnerability
Vulnerability Description
A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, which can be used to achieve remote code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9161
Credits & Attribution
No credits recorded in the NVD database.
References
More from Rockwell Automation
View All →CVE-2025-9466
ArmorStart® LT - Multiple Denial-of-Service Vulnerabilities
High
8.7
CVE-2025-9465
ArmorStart® LT - Multiple Denial-of-Service Vulnerabilities
High
8.7
CVE-2025-9464
Rockwell Automation ArmorStart® LT - Multiple Denial-of-Service Vulnerabilities
High
8.7
CVE-2025-9437
Rockwell Automation ArmorStart® AOP Denial-of-Service Vulnerability
High
8.7
CVE-2025-9368
432ES-IG3 Series A Denial-of-Service Vulnerability
High
8.7
Affected Vendor
Rockwell Automation
View all reports →Affected Software
FactoryTalk Optix
Vulnerable Versions:
All Versions 1.5.0 - 1.5.7
Timeline
Official Publish:
September 9th, 2025
Last Modified:
September 9th, 2025
Added to House:
July 22nd, 2026