CVE-2025-9160 describes a high-severity code execution vulnerability affecting an unspecified product. An attacker with physical access can exploit a flaw in the controller's maintenance menu using a crafted payload, leading to arbitrary code execution. The CVSS score of 7.0 reflects the high impact on confidentiality, integrity, and availability, despite requiring physical access. Currently, there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and minimal community discussion or media coverage, indicating it is not actively exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Rockwell Automation | CompactLogix® 5480 | Version 32 - 37.011 w Windows package (2.1.0) Win10 v1607CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.