Back

HIGH

Rockwell Automation FactoryTalk® Linx Network Browser Security Bypass Vulnerability

Published Aug 14, 2025

Description

A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, and delete FTLinx drivers.

Affected products

Remediation

Vendor solution

Upgrade to version 6.50 or later.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Rockwell
Published Aug 14, 2025
Updated Aug 14, 2025
Reserved Jul 21, 2025
CISA Vulnrichment
Updated Aug 14, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a