CVE-2025-55069
A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software implements a predictable seed for its pseudo-random number generator, which compromises the security of the generated private keys.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.31%
- CWE
- CWE-337
- Published
- 2025-09-23
- Last modified
- 2026-03-12
Affected products
- AutomationDirect CLICK PLUS C0-0x CPU firmware
- AutomationDirect CLICK PLUS C0-1x CPU firmware
- AutomationDirect CLICK PLUS C2-x CPU firmware
Weakness type
Related vulnerabilities
- CVE-2026-26018 — CoreDNS Loop Detection Denial of Service Vulnerability
- CVE-2026-25235 — PEAR Has a Predictable Verification Hash in Election Account Requests
- CVE-2025-62710 — Sakai kernel-impl: predictable PRNG used to generate server‑side encryption key in EncryptionUtilityServiceImpl
- CVE-2025-20613 — Predictable Seed in Pseudo-Random Number Generator (PRNG) in the firmware for some Intel(R) TDX may...
- CVE-2025-7770 — Predictable Seed in Pseudo-Random Number Generator (PRNG) in Tigo Energy Cloud Connect Advanced
- CVE-2024-7558 — JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju...
- CVE-2024-22194 — cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code
- CVE-2023-49343 — Temporary data passed between application components by Budgie Extras Dropby applet could...