# CVE-2025-67652

## Summary

- **CVE ID:** CVE-2025-67652
- **Severity:** MEDIUM
- **CVSS Score:** 6.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N)
- **CWE:** CWE-261
- **Published:** Jan 22, 2026
- **Last Modified:** Mar 13, 2026

## Description

An attacker with access to the project file could use the exposed 
credentials to impersonate users, escalate privileges, or gain 
unauthorized access to systems and services. The absence of robust 
encryption or secure handling mechanisms increases the likelihood of 
this type of exploitation, leaving sensitive information more 
vulnerable.

## Affected Products

- AutomationDirect — CLICK Programmable Logic Controller (C0-0x)
- AutomationDirect — CLICK Programmable Logic Controller (C0-1x)
- AutomationDirect — CLICK Programmable Logic Controller (C2-x)
- AutomationDirect — CLICK Programmable Logic Controller (V3.90)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-02)
- [CNA](https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-022-02.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 1.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._