CVE-2025-62498: AutomationDirect Productivity Suite Relative Path Traversal
A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version
4.4.1.19. The vulnerability allows an attacker who can tamper with a productivity project to execute arbitrary code on the machine where the project is opened.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62498?
CVE-2025-62498 is a critical severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-62498?
To mitigate CVE-2025-62498, users should update their AutomationDirect Productivity Suite software to the latest version.
What type of attack does CVE-2025-62498 enable?
CVE-2025-62498 allows attackers to execute arbitrary code through a relative path traversal exploit in affected software.
Which versions of AutomationDirect Productivity Suite are affected by CVE-2025-62498?
CVE-2025-62498 impacts AutomationDirect Productivity Suite version 4.4.1.19 and prior.
What should I do if I cannot update to a fixed version for CVE-2025-62498?
If unable to update for CVE-2025-62498, consider implementing strict access controls to limit the potential exploitation of this vulnerability.