# CVE-2025-59484

## Summary

- **CVE ID:** CVE-2025-59484
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N)
- **CWE:** CWE-327
- **Published:** Sep 23, 2025
- **Last Modified:** Mar 13, 2026

## Description

The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software uses an insecure implementation of the RSA encryption algorithm.

## Affected Products

- AutomationDirect — CLICK PLUS C0-0x CPU firmware (0)
- AutomationDirect — CLICK PLUS C0-1x CPU firmware (0)
- AutomationDirect — CLICK PLUS C2-x CPU firmware (0)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-25-266-01)
- [CNA](https://www.automationdirect.com/support/software-downloads)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.12%
- **EPSS Percentile:** 2.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._