Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24070 | In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin's acceptability (for later Dashboard installation) is set by the "emqx ctl plugins allow" CLI command. |
Tue, 12 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 Aug 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Emqx
Emqx emqx |
|
| Vendors & Products |
Emqx
Emqx emqx |
Sun, 10 Aug 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin's acceptability (for later Dashboard installation) is set by the "emqx ctl plugins allow" CLI command. | |
| Weaknesses | CWE-754 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-12T14:27:35.318Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-52136
Updated: 2025-08-12T14:27:32.387Z
Status : Deferred
Published: 2025-08-10T04:15:33.913
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-52136
No data.
OpenCVE Enrichment
Updated: 2025-08-12T07:41:45Z
EUVD