CVE-2025-7972

A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, and delete FTLinx drivers.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:factorytalk_linx:*:*:*:*:*:*:*:*

History

29 Oct 2025, 20:30

Type Values Removed Values Added
First Time Rockwellautomation
Rockwellautomation factorytalk Linx
References () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1735.html - () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1735.html - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
Summary
  • (es) Existe un problema de seguridad en FactoryTalk Linx Network Browser. Al modificar process.env.NODE_ENV a "development", el atacante puede deshabilitar la validación del token FTSP. Esta omisión permite el acceso para crear, actualizar y eliminar controladores FTLinx.
CPE cpe:2.3:a:rockwellautomation:factorytalk_linx:*:*:*:*:*:*:*:*

14 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-14 15:15

Updated : 2025-10-29 20:30


NVD link : CVE-2025-7972

Mitre link : CVE-2025-7972

CVE.ORG link : CVE-2025-7972


JSON object : View

Products Affected

rockwellautomation

  • factorytalk_linx
CWE
CWE-286

Incorrect User Management