CVE-2025-7972: Rockwell Automation FactoryTalk® Linx Network Browser Security Bypass Vulnerability
A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODEENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, and delete FTLinx drivers.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7972?
CVE-2025-7972 is considered a high severity vulnerability due to its potential to bypass FTSP token validation.
How do I fix CVE-2025-7972?
To fix CVE-2025-7972, ensure that the process.env.NODE_ENV is not set to 'development' in the FactoryTalk Linx Network Browser.
What systems are affected by CVE-2025-7972?
CVE-2025-7972 affects the Rockwell Automation FactoryTalk Linx Network Browser.
What actions can be taken by exploiting CVE-2025-7972?
Exploitation of CVE-2025-7972 allows an attacker to create, update, and delete FTLinx drivers without proper authorization.
Is there any public information available about CVE-2025-7972?
Yes, additional details regarding CVE-2025-7972 can typically be found in security advisories from Rockwell Automation.