CVE-2025-52136
Estado: AplazadaBaja (3)—
In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin's acceptability (for later Dashboard installation) is set by the "emqx ctl plugins allow" CLI command.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N
- Puntuación base: 3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.28%
- Percentil entre todas las CVEs puntuadas: 18
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-754
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-52136",
"cveTags": [
{
"tags": [
"disputed"
],
"sourceIdentifier": "cve@mitre.org"
}
],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-52136",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-08-12T14:27:21.450060Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 3,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 1.3
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "EMQX",
"product": "EMQX",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "5.8.6",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-08-10T04:15:33.913",
"references": [
{
"url": "https://docs.emqx.com/en/emqx/latest/dashboard/introduction.html",
"source": "cve@mitre.org"
},
{
"url": "https://docs.emqx.com/en/emqx/latest/deploy/install-docker.html",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/ricardojoserf/emqx-RCE",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/ricardojoserf/emqx-RCE",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"description": [
{
"lang": "en",
"value": "CWE-754"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin's acceptability (for later Dashboard installation) is set by the \"emqx ctl plugins allow\" CLI command."
},
{
"lang": "es",
"value": "En EMQX anterior a la versión 5.8.6, los administradores podían instalar complementos nuevos a su elección mediante la interfaz web del Dashboard. NOTA: El proveedor considera que este es el comportamiento previsto; sin embargo, la versión 5.8.6 añade una función de defensa en profundidad que permite configurar la aceptabilidad de un complemento (para su posterior instalación en el Dashboard) mediante el comando CLI \"emqx ctl plugins allow\"."
}
],
"lastModified": "2026-06-17T09:36:01.520",
"sourceIdentifier": "cve@mitre.org"
}