CVE-2025-58069: AutomationDirect CLICK PLUS Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software contains a hard-coded AES key used to protect the initial messages of a new KOPS session.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58069?
CVE-2025-58069 is considered a high severity vulnerability due to the use of a hard-coded cryptographic key in firmware version 3.60 of the Click Plus PLC.
How do I fix CVE-2025-58069?
To fix CVE-2025-58069, upgrade the firmware of your Click Plus PLC to version 3.71 or later.
Which products are affected by CVE-2025-58069?
CVE-2025-58069 affects AutomationDirect CLICK PLUS C0-0x, C0-1x, and C2-x CPU firmware versions up to 3.71.
What is the impact of exploiting CVE-2025-58069?
Exploiting CVE-2025-58069 allows attackers to potentially decrypt sensitive information and establish unauthorized access during KOPS sessions.
Is there a workaround for CVE-2025-58069?
There are no documented workarounds for CVE-2025-58069; upgrading to the latest firmware is the recommended action.