CVE-2025-58069: Automationdirect Click Plus c0-0x CPU Firmware
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software contains a hard-coded AES key used to protect the initial messages of a new KOPS session.
Affected products
- Automationdirect Click Plus c0-0x CPU Firmware: before v3.71 (fixed in v3.71)
- Automationdirect Click Plus c0-1x CPU Firmware: before v3.71 (fixed in v3.71)
- Automationdirect Click Plus c2-X CPU Firmware: before v3.71 (fixed in v3.71)
Published 2025-09-23. Last modified 2026-06-17.