CVE-2025-67652
An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges, or gain unauthorized access to systems and services. The absence of robust encryption or secure handling mechanisms increases the likelihood of this type of exploitation, leaving sensitive information more vulnerable.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.1
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- EPSS probability
- 0.10%
- CWE
- CWE-261
- Published
- 2026-01-22
- Last modified
- 2026-03-13
Affected products
- AutomationDirect CLICK Programmable Logic Controller
- AutomationDirect CLICK Programmable Logic Controller
- AutomationDirect CLICK Programmable Logic Controller
- AutomationDirect CLICK Programmable Logic Controller
Weakness type
Related vulnerabilities
- CVE-2026-63424 — During an internal security assessment, an improperly protected key was discovered in Lenovo Dock...
- CVE-2026-67596 — CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfg
- CVE-2026-53692 — Weak hashing algorithm in Redeight CMS
- CVE-2026-40639 — Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated...
- CVE-2026-25607 — Weak password encoding in STER
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2026-0809 — Weak KSeF token encoding in Streamsoft Prestiż
- CVE-2024-52334 — A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected...