CVE-2025-55038: AutomationDirect CLICK PLUS Missing Authorization
An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Through the KOPR protocol utilized by the Remote PLC application, authenticated users with low-level access permissions can exploit this vulnerability to read and modify PLC variables beyond their intended authorization level.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55038?
CVE-2025-55038 is classified as a medium severity authorization bypass vulnerability.
How do I fix CVE-2025-55038?
To fix CVE-2025-55038, update the firmware of the affected CLICK PLUS C0-0x, C0-1x, or C2-x CPU to version 3.71 or later.
Who is affected by CVE-2025-55038?
Organizations using affected versions of CLICK PLUS C0-0x, C0-1x, or C2-x CPU firmware are at risk from CVE-2025-55038.
What can an attacker do using CVE-2025-55038?
An attacker can exploit CVE-2025-55038 to gain unauthorized access and potentially read or modify sensitive information.
Which versions of CLICK PLUS firmware are impacted by CVE-2025-55038?
Versions up to but not including 3.71 of CLICK PLUS C0-0x, C0-1x, and C2-x CPU firmware are impacted by CVE-2025-55038.