CVE-2025-61934
A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
- EPSS probability
- 0.62%
- CWE
- CWE-1327
- Published
- 2025-10-23
- Last modified
- 2026-03-12
Affected products
- AutomationDirect Productivity Suite
- AutomationDirect Productivity 3000 P3-622 CPU
- AutomationDirect Productivity 3000 P3-550E CPU
- AutomationDirect Productivity 3000 P3-530 CPU
- AutomationDirect Productivity 2000 P2-622 CPU
- AutomationDirect Productivity 2000 P2-550 CPU
- AutomationDirect Productivity 1000 P1-550 CPU
- AutomationDirect Productivity 1000 P1-540 CPU
Weakness type
Related vulnerabilities
- CVE-2026-75021 — fastify-cli vulnerable to remote code execution via ignored explicit Inspector bind address
- CVE-2026-20212 — Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability
- CVE-2026-82456 — argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP
- CVE-2026-72924 — GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
- CVE-2026-16713 — IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
- CVE-2026-55641 — 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
- CVE-2026-0481 — Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a...
- CVE-2026-42503 — Accidental binding to INADDR_ANY might lead to RCE in golang.org/x/tools/gopls