CVE-2025-55069: Automationdirect Click Plus c0-0x CPU Firmware
High severity, CVSS 8.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software implements a predictable seed for its pseudo-random number generator, which compromises the security of the generated private keys.
Affected products
- Automationdirect Click Plus c0-0x CPU Firmware: before v3.71 (fixed in v3.71)
- Automationdirect Click Plus c0-1x CPU Firmware: before v3.71 (fixed in v3.71)
- Automationdirect Click Plus c2-X CPU Firmware: before v3.71 (fixed in v3.71)
Published 2025-09-23. Last modified 2026-06-17.