CVE-2025-57882: AutomationDirect CLICK PLUS Improper Resource Shutdown or Release
An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions in the Remote PLC application.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57882?
CVE-2025-57882 is categorized as a medium severity vulnerability due to its potential to cause denial-of-service attacks.
How do I fix CVE-2025-57882?
To mitigate CVE-2025-57882, update the affected Click Plus C2-03CPU-2 device firmware to version 3.71 or later.
Which products are affected by CVE-2025-57882?
CVE-2025-57882 affects the Click Plus C0-0x, C0-1x, and C2-x CPU firmware versions up to 3.71.
What type of attack can be performed using CVE-2025-57882?
CVE-2025-57882 allows an unauthenticated attacker to perform a denial-of-service attack by exhausting device sessions.
Is authentication required to exploit CVE-2025-57882?
No, CVE-2025-57882 can be exploited by unauthenticated attackers.