CVE-2024-25136: Automationdirect C-More EA9-Pgmsw Firmware
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the content.
Affected products
- Automationdirect C-More EA9-Pgmsw Firmware: up to and including 6.77
- Automationdirect C-More EA9-Rhmi Firmware: up to and including 6.77
- Automationdirect C-More EA9-t10cl Firmware: up to and including 6.77
- Automationdirect C-More EA9-t10wcl Firmware: up to and including 6.77
- Automationdirect C-More EA9-t12cl Firmware: up to and including 6.77
- Automationdirect C-More EA9-t15cl-R Firmware: up to and including 6.77
- Automationdirect C-More EA9-t15cl Firmware: up to and including 6.77
- Automationdirect C-More EA9-t6cl Firmware: up to and including 6.77
- Automationdirect C-More EA9-t7cl-R Firmware: up to and including 6.77
- Automationdirect C-More EA9-t7cl Firmware: up to and including 6.77
- Automationdirect C-More EA9-t8cl Firmware: up to and including 6.77
- Automationdirect C-More EA9 HMI EA0-t7cl-R: up to and including 6.77
- Automationdirect C-More EA9 HMI EA9-Pgmsw: up to and including 6.77
- Automationdirect C-More EA9 HMI EA9-Rhmi: up to and including 6.77
- Automationdirect C-More EA9 HMI EA9-t10cl: up to and including 6.77
- Automationdirect C-More EA9 HMI EA9-t10wcl: up to and including 6.77
- Automationdirect C-More EA9 HMI EA9-t12cl: up to and including 6.77
- Automationdirect C-More EA9 HMI EA9-t15cl: up to and including 6.77
- Automationdirect C-More EA9 HMI EA9-t15cl-R: up to and including 6.77
- Automationdirect C-More EA9 HMI EA9-t6cl: up to and including 6.77
- Automationdirect C-More EA9 HMI EA9-t7cl: up to and including 6.77
- Automationdirect C-More EA9 HMI EA9-t8cl: up to and including 6.77
Published 2024-03-26. Last modified 2026-06-17.