CVE-2025-52136: Low severity EMQ EMQX vulnerability
In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin's acceptability (for later Dashboard installation) is set by the "emqx ctl plugins allow" CLI command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52136?
CVE-2025-52136 is considered a medium severity vulnerability due to the potential for unauthorized plugin installations.
How do I fix CVE-2025-52136?
To fix CVE-2025-52136, upgrade EMQX to version 5.8.6 or later, which includes improved security features.
What is the impact of CVE-2025-52136?
The impact of CVE-2025-52136 is that it allows administrators to install arbitrary plugins, potentially leading to unauthorized access or control.
Who is affected by CVE-2025-52136?
CVE-2025-52136 affects all versions of EMQX prior to version 5.8.6.
Is CVE-2025-52136 an intended behavior?
Yes, the supplier states that the ability to install arbitrary plugins via the Dashboard is intended, but security improvements were added in version 5.8.6.