CVE-2025-7972

A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, and delete FTLinx drivers.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:factorytalk_linx:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-14 15:15

Updated : 2025-10-29 20:30


NVD link : CVE-2025-7972

Mitre link : CVE-2025-7972

CVE.ORG link : CVE-2025-7972


JSON object : View

Products Affected

rockwellautomation

  • factorytalk_linx
CWE
CWE-286

Incorrect User Management