Vulnerability Description
In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin's acceptability (for later Dashboard installation) is set by the "emqx ctl plugins allow" CLI command.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://docs.emqx.com/en/emqx/latest/dashboard/introduction.html
- https://docs.emqx.com/en/emqx/latest/deploy/install-docker.html
- https://github.com/ricardojoserf/emqx-RCE
- https://github.com/ricardojoserf/emqx-RCE
FAQ
What is CVE-2025-52136?
CVE-2025-52136 is a vulnerability with a CVSS score of 3.0 (LOW). In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a def...
How severe is CVE-2025-52136?
CVE-2025-52136 has been rated LOW with a CVSS base score of 3.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-52136?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.