CVE-2025-36535: Automationdirect Mb-Gateway

Critical severity, CVSS 10.0. EPSS: 1% chance of exploitation in the next 30 days.

The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the environment and exposed functionality.

Affected products

Published 2025-05-21. Last modified 2026-06-17.