Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-55069 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software implements a predictable seed for its pseudo-random number generator, which compromises the security of the generated private keys.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-337Predictable Seed in Pseudo-Random Number Generator (PRNG)[email protected]

Affected Products

ProductVersions
AutomationDirect Click Plus C0-0x CPU
< 3.71

CPE

  • cpe:2.3:o:automationdirect:click_plc_firmware:*:*:*:*:*:*:*:*

Remediation

  • Upgrade: 3.80moderate efforthttps://www.automationdirect.com/support/software-downloads
  • Mitigation:low effort

    Disconnect the CLICK PLUS PLC from external networks (e.g., the internet or corporate LAN) to reduce exposure.

  • Mitigation:low effort

    Use only trusted, dedicated internal networks or air-gapped systems for device communication.

  • Mitigation:low effort

    Restrict both physical and logical access to authorized personnel only.

  • Mitigation:low effort

    Configure whitelisting so that only trusted, pre-approved applications are allowed to run. Block any unauthorized software.

  • Mitigation:low effort

    Use antivirus or EDR tools and configure host-based firewalls to block unauthorized access attempts.

  • Mitigation:low effort

    Enable and regularly review system logs to detect suspicious or unauthorized activity.

  • Mitigation:low effort

    Maintain secure, tested backups of the PLC and its configurations to minimize downtime in case of an incident.

  • Mitigation:low effort

    Continuously evaluate risks associated with running outdated firmware and adjust compensating measures accordingly.

AutomationDirect Click Plus C0-1x CPU
All versions

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • No remediation found in references.
AutomationDirect Click Plus C2-x CPU
All versions

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • No remediation found in references.

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-55069
NVD Published Date:
Sep 23, 2025
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2025-55069 Details - Not Deferred