CVE-2025-58473: Automationdirect Click Plus c0-0x CPU Firmware
Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.
An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions of the Click Programming Software.
Affected products
- Automationdirect Click Plus c0-0x CPU Firmware: before v3.71 (fixed in v3.71)
- Automationdirect Click Plus c0-1x CPU Firmware: before v3.71 (fixed in v3.71)
- Automationdirect Click Plus c2-X CPU Firmware: before v3.71 (fixed in v3.71)
Published 2025-09-23. Last modified 2026-06-17.