PT-2025-32464 · Emqx · Emqx

Ricardojoserf

·

Published

2025-08-10

·

Updated

2025-08-10

·

CVE-2025-52136

CVSS v3.1

3.0

Low

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: EMQX versions prior to 5.8.6
Description: Administrators could install arbitrary novel plugins via the Dashboard web interface. The supplier considers this intended behavior; however, version 5.8.6 introduced a defense-in-depth feature requiring CLI approval for plugin installation using the emqx ctl plugins allow command.
Recommendations: Upgrade to version 5.8.6 or later.

Exploit

Fix

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2025-52136

Affected Products

Emqx