CVE-2025-61934: Automationdirect Productivity 1000 p1-540 CPU

Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.

A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine

Affected products

Published 2025-10-23. Last modified 2026-06-17.