You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
network browser
About this tag
The network browser tag on WindowsForum.com covers discussions about Rockwell Automation's FactoryTalk Linx, a communications and device-discovery layer used in industrial control systems. Recent threads focus on CVE-2025-7972, an improper access control vulnerability that can be triggered by setting Node.js's process.env.NODE_ENV to "development," allowing attackers to bypass FTSP token validation and create, update, or delete FTLinx drivers. CISA advises upgrading to FactoryTalk Linx v6.50 to mitigate this privilege abuse risk. Topics include security patches, vulnerability details, and remediation steps for enterprise IT and industrial environments.
A recently republished CISA advisory warns that Rockwell Automation’s FactoryTalk Linx contains a serious improper access control flaw that—when triggered by setting Node.js’ process.env.NODE_ENV to "development"—can disable FTSP token validation and allow an attacker to create, update, or...
Rockwell’s advisory republication this week exposes a subtle but serious weakness in FactoryTalk Linx that—if present in your environment—lets an attacker bypass FTSP token validation and perform privileged driver management actions, and CISA is clear: update to FactoryTalk Linx v6.50 as the...