CVE-2025-36535: AutomationDirect MB-Gateway Missing Authentication for Critical Function
The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the environment and exposed functionality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36535?
CVE-2025-36535 is considered critical due to the lack of authentication and access controls allowing unrestricted remote access.
How do I fix CVE-2025-36535?
To fix CVE-2025-36535, implement appropriate access controls and authentication mechanisms on the embedded web server.
Which software is affected by CVE-2025-36535?
CVE-2025-36535 affects all versions of the AutomationDirect MB-Gateway.
What are the potential impacts of CVE-2025-36535?
Potential impacts of CVE-2025-36535 include configuration changes, operational disruption, or arbitrary code execution.
Is CVE-2025-36535 exploitable remotely?
Yes, CVE-2025-36535 is exploitable remotely due to the absence of authentication and access controls.