CVE-2025-61934: AutomationDirect Productivity Suite Binding to an Unrestricted IP Address CWE-1327
A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61934?
CVE-2025-61934 has a critical severity level as it allows unauthenticated remote access to sensitive files.
How do I fix CVE-2025-61934?
To mitigate CVE-2025-61934, upgrade to the latest version of the Productivity Suite software.
What products are affected by CVE-2025-61934?
Products affected by CVE-2025-61934 include AutomationDirect Productivity Suite v4.4.1.19 and prior, among others listed.
Can CVE-2025-61934 lead to data loss?
Yes, CVE-2025-61934 enables attackers to read, write, or delete arbitrary files, potentially leading to data loss.
What kind of attacks can exploit CVE-2025-61934?
CVE-2025-61934 can be exploited by an unauthenticated remote attacker, posing severe security risks.