PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-58069 AutomationDirect CVE debrief

CISA published ICSA-25-266-01 on 2025-09-23 for CVE-2025-58069. The advisory says AutomationDirect CLICK PLUS PLC firmware version 3.60 contains a hard-coded AES key used to protect the initial messages of a new KOPS session. AutomationDirect recommends updating affected CLICK PLUS CPU firmware lines to V3.80 and, until that can be done, applying compensating controls such as network isolation, trusted internal communications, restricted access, application whitelisting, endpoint protection, logging, backups, and ongoing risk review.

Vendor
AutomationDirect
Product
CLICK PLUS C0-0x CPU firmware
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2025-09-23
Original CVE updated
2025-09-23
Advisory published
2025-09-23
Advisory updated
2025-09-23

Who should care

Operators, integrators, and maintenance teams responsible for AutomationDirect CLICK PLUS C0-0x, C0-1x, and C2-x CPU firmware, especially environments running firmware 3.60 or exposed to broader networks.

Technical summary

The issue is a hard-coded cryptographic key in CLICK PLUS firmware 3.60. According to the advisory, the AES key protects the initial messages of a new KOPS session. The supplied CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, indicating a network-reachable issue with low confidentiality impact and no integrity or availability impact in the provided scoring.

Defensive priority

Medium. Prioritize upgrading exposed or operationally sensitive PLC deployments first, especially where the device is reachable beyond a tightly controlled industrial network.

Recommended defensive actions

  • Update CLICK PLUS firmware to V3.80 as recommended by AutomationDirect.
  • If immediate updating is not possible, isolate the PLC from external networks and use trusted, dedicated internal or air-gapped communications.
  • Restrict physical and logical access to authorized personnel only.
  • Use application whitelisting to allow only trusted software.
  • Enable endpoint protection and host-based firewalls where applicable.
  • Enable and regularly review logs for suspicious or unauthorized activity.
  • Maintain secure, tested backups of PLC configurations and recovery procedures.
  • Reassess operational risk while running outdated firmware until remediation is complete.

Evidence notes

The supplied CISA CSAF advisory for ICSA-25-266-01 states that firmware 3.60 is affected and that AutomationDirect recommends upgrading to V3.80. The advisory also lists compensating controls for systems that cannot be updated immediately. The provided enrichment does not list a CISA KEV entry for this CVE.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-58069 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-58069

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-58069 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-58069

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-266-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-266-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.