PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-36535 AutomationDirect CVE debrief

CVE-2025-36535 is a critical flaw in AutomationDirect MB-Gateway where the embedded webserver lacks authentication and access controls. According to CISA’s advisory published on 2025-05-20, remote users may gain unrestricted access and potentially change configuration, disrupt operations, or trigger more severe impact depending on the exposed functionality and environment.

Vendor
AutomationDirect
Product
MB-Gateway
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2025-05-20
Original CVE updated
2025-05-20
Advisory published
2025-05-20
Advisory updated
2025-05-20

Who should care

Industrial control system operators, plant engineers, OT/ICS administrators, and security teams responsible for AutomationDirect MB-Gateway deployments should treat this as urgent. Any environment exposing the device to untrusted networks, especially the internet, is at elevated risk.

Technical summary

CISA’s advisory identifies the affected product as AutomationDirect MB-Gateway: vers:all/*, indicating all versions are affected in the advisory scope. The core issue is an embedded webserver that does not enforce authentication or access control, so a remote attacker can interact with exposed management functionality without credentials. The advisory warns this can result in configuration changes, operational disruption, or arbitrary code execution depending on how the device is deployed and what functions are reachable.

Defensive priority

Immediate. This is a network-reachable, unauthenticated management exposure with a CVSS v3.1 base score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Prioritize isolation, exposure reduction, and replacement planning over routine patching, because the vendor notes the hardware limitation prevents a proper access-control update.

Recommended defensive actions

  • Replace MB-Gateway with AutomationDirect EKI-1221-CE as recommended by the vendor.
  • Ensure affected devices are not accessible from the internet or untrusted networks; place them behind firewalls.
  • Use dedicated secure internal networks or air-gapped systems for communication with programmable devices.
  • Restrict physical and logical access to authorized personnel only.
  • Implement application whitelisting to allow only pre-approved and trusted access.
  • Enable logging and monitoring of system activity and regularly review logs for suspicious behavior.
  • Maintain secure backups of workstations and configurations, and test recovery procedures.
  • Begin evaluating and migrating to supported hardware with active vendor support.

Evidence notes

This debrief is based on CISA advisory ICSA-25-140-09 and the associated CSAF source item for CVE-2025-36535. The advisory explicitly states the embedded webserver lacks authentication and access controls, and it lists the affected product as AutomationDirect MB-Gateway: vers:all/*. The vendor remediation guidance in the source corpus recommends replacement with EKI-1221-CE and interim exposure-reduction measures. No CISA KEV entry was provided in the supplied data.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-36535 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-36535

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-36535 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36535

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-140-09.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-140-09

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.