CVE-2025-57882 Details
Description
An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions in the Remote PLC application.
A denial-of-service vulnerability has been identified in the AutomationDirect Click Plus C2-03CPU-2 device running firmware version 3.60. This vulnerability allows an unauthenticated attacker to exhaust all available device sessions in the Remote PLC application, causing a denial-of-service condition.
Users are advised to update the Click Plus C2-03CPU-2 device firmware to version 3.80. If the update cannot be applied immediately, it is recommended to isolate the device from external networks, restrict access to authorized personnel, and use endpoint protection tools to block unauthorized access attempts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2025CISA-ADP
Assessed Sep 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.automationdirect.com/support/software-downloads | [email protected] | Vendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-266-01 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AutomationDirect Click Plus C2-03CPU-2 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2025 | New CVE Received | [email protected] |
Volerion