CVE-2025-52136 - CERT CVE
ID CVE-2025-52136
Sažetak In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin's acceptability (for later Dashboard installation) is set by the "emqx ctl plugins allow" CLI command.
Reference
CVSS
Base: 3.0
Impact: 1.4
Exploitability:1.3
Pristup
VektorSloženostAutentikacija
NETWORK HIGH HIGH
Impact
PovjerljivostCjelovitostDostupnost
NONE LOW NONE
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N
Zadnje važnije ažuriranje 11-08-2025 - 18:32
Objavljeno 10-08-2025 - 04:15