CVE-2025-58473: AutomationDirect CLICK PLUS Improper Resource Shutdown or Release
An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions of the Click Programming Software.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58473?
CVE-2025-58473 is classified as a denial-of-service vulnerability with a significant impact if exploited.
How do I fix CVE-2025-58473?
To mitigate CVE-2025-58473, users should upgrade to firmware version 3.71 or later for the affected Click Plus CPUs.
What devices are affected by CVE-2025-58473?
CVE-2025-58473 affects AutomationDirect CLICK PLUS C0-0x, C0-1x, and C2-x CPU firmware versions up to 3.71.
What type of attack can be performed using CVE-2025-58473?
CVE-2025-58473 can be exploited by an unauthenticated attacker to perform a denial-of-service attack.
Is authentication required to exploit CVE-2025-58473?
No, CVE-2025-58473 can be exploited without authentication, allowing remote attackers to exhaust device sessions.