CVE-2025-57882: Automationdirect Click Plus c0-0x CPU Firmware

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions in the Remote PLC application.

Affected products

Published 2025-09-23. Last modified 2026-06-17.