Skip to content
CISA issues multiple ICS advisories, details DoS vulnerability risk in Rockwell devices used ...

CISA issues multiple ICS advisories, details DoS vulnerability risk in Rockwell devices used ...

Industrialcyber.Co • January 14, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published on Tuesday three ICS advisories and updated an earlier one, providing timely information current security issues, vulnerabilities, and exploits surrounding ICS. The agency warned of the presence of vulnerabilities in equipment from Rockwell Automation and YoSmart. It updated an advisory addressing Güralp Systems hardware used across the global critical manufacturing sector.

CISA disclosed that Rockwell Automation 432ES-IG3 Series A devices are affected by CVE-2025-9368, a vulnerability with a CVSS v3 base score of 7.5. The issue involves an allocation of resources without proper limits or throttling, and successful exploitation could result in a denial-of-service condition. Rockwell Automation reported this vulnerability to CISA.

Deployed across the critical manufacturing sector, the agency revealed that a security issue exists within 432ES-IG3 Series A, which affects GuardLink EtherNet/IP Interface, resulting in a denial-of-service condition. A manual power cycle is required to recover the device.

Rockwell Automation recommends users of the 432ES-IG3 Series A update to V2.001.9 or later. The upgrade can be downloaded from the company website. Users of the affected software, who are not able to upgrade to one of the corrected versions, should follow the company’s security best practices.

In another advisory, CISA revealed that Rockwell Automation FactoryTalk DataMosaix Private Cloud is affected by a vulnerability tracked as CVE-2025-12807. The issue carries a CVSS v3 base score of 8.8 and involves improper neutralization of special elements used in an SQL command, commonly known as SQL injection. Successful exploitation could allow an attacker to perform unauthorized sensitive database operations.

The affected product versions include Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 7.11, 8.00, and 8.01 used across the critical manufacturing sector. CISA noted that a security issue was discovered in DataMosaix Private Cloud, allowing users with low privileges to perform sensitive database operations through exposed Application Programming Interface (API) endpoints.

Rockwell Automation encourages users of the affected software to update to FactoryTalk DataMosaix Private Cloud to Version 8.01.02 or later.

In another advisory, CISA revealed that the YoSmart YoLink Smart Hub is affected. Vulnerabilities have been identified in the YoSmart server (CVE-2025-59449, CVE-2025-59451), the YoLink Smart Hub (CVE-2025-59452), and the YoLink mobile application (CVE-2025-59448). Deployed across the global communications sector, the agency added that “Successful exploitation of these vulnerabilities could allow an attacker to remotely control other users’ smart devices, intercept sensitive data, and hijack sessions.”

Nick Cerne of Bishop Fox reported these vulnerabilities to CISA. The YoSmart YoLink Smart Hub has been assigned a CVSS v3 score of 5.8. The device is affected by multiple vulnerabilities, including incorrect authorization, the generation of predictable numbers or identifiers, and the cleartext transmission of sensitive information.

The advisory noted that the YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-account attacks, allowing an attacker to remotely operate affected devices if the attacker obtains the associated device IDs. Because YoLink device IDs are predictable, an attacker can exploit this to gain full control over any other YoLink user’s devices.

It added that the YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device’s MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50.

Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to control affected devices. This affects YoLink Mobile Application 1.40.41 and YoLink MQTT Broker. The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes.

CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as minimizing network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet, locating control system networks and remote devices behind firewalls, and isolating them from business networks.

When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also, recognize that a VPN is only as secure as the connected devices.

CISA reminds organizations to perform impact analysis and risk assessment prior to deploying defensive measures. It also provides a section for control systems security recommended practices on the ICS webpage. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.