CVE 8.2 HIGH

AutomationDirect CLICK PLUS Improper Resource Shutdown or Release_CVE-2025-57882

8.2 / 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Description

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions in the Remote PLC application.

Basic Information

ID CVE-2025-57882
Source icscert
Published Sep 23, 2025 at 22:27

Affected Product

Vendor AutomationDirect
Product CLICK PLUS C0-0x CPU firmware
Affected Versions AutomationDirect CLICK PLUS C0-0x CPU firmware 0
AutomationDirect CLICK PLUS C0-1x CPU firmware 0
AutomationDirect CLICK PLUS C2-x CPU firmware 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.