CVE-2025-59484
8.3AutomationDirect · CLICK PLUS PLC
AutomationDirect CLICK PLUS PLCs use an insecure implementation of the RSA encryption algorithm, creating a vulnerability due to the use of a broken or risky cryptographic algorithm.
Executive summary
A critical cryptographic vulnerability in AutomationDirect CLICK PLUS PLC firmware, identified as CVE-2025-59484, exposes industrial control systems to potential unauthorized access and data compromise.
Vulnerability
This vulnerability involves the use of an insecure, broken cryptographic implementation of the RSA algorithm within the device firmware. The flaw is exploitable over the network by an unauthenticated attacker, requiring only user interaction.
Business impact
The use of weak cryptography poses a significant risk to the integrity and confidentiality of communication between the PLC and management interfaces. With a CVSS score of 8.3, this flaw enables potential unauthorized command execution or data interception, which could lead to operational disruption or physical process interference in industrial environments.
Remediation
Immediate Action: Update all affected CLICK PLUS PLC firmware to version 3.80 or later as recommended by the vendor.
Proactive Monitoring: Monitor network traffic for unusual patterns or unauthorized connection attempts directed at the PLC management interfaces.
Compensating Controls: Implement strict network isolation by disconnecting the PLC from the internet or corporate LANs, and ensure all communications occur over air-gapped or dedicated, trusted internal networks.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical role of PLCs in industrial automation, the identified cryptographic weakness represents a substantial security gap. Organizations using the affected AutomationDirect CLICK PLUS hardware should prioritize firmware upgrades to version 3.80 immediately. Where patching is not feasible, network segmentation remains the most effective strategy to prevent unauthorized access until remediation is completed.
Sources
Originally found and disclosed by Luca Borzacchiello and Diego Zaffaroni of Nozomi Networks reported these vulnerabilities to Automation Direct., per the CVE Program record.