A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, and delete FTLinx drivers.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XRockwellautomation Factorytalk Linx
APPRockwellautomation< 6.50
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
Related vulnerabilities
CVE-2020-27251CRITICAL9.8PL ✓same product
Heap overflow w Rockwell Automation FactoryTalk Linx umożliwia RCE
CVE-2020-12001CRITICAL9.8PL ✓same product
RCE i path traversal w Rockwell Automation FactoryTalk Linx i RSLinx Classic
CVE-2025-9067HIGH8.5same product
A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated at...
CVE-2025-9068HIGH8.5same product
A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repai...
CVE-2023-29464HIGH8.2same product
FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read d...