MEDIUM
AutomationDirect CLICK Programmable Logic Controller Weak Encoding for Password
Published Jan 22, 2026
6.1
MEDIUMCVSS 3.1
EPSS 0.11%
Description
An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges, or gain unauthorized access to systems and services. The absence of robust encryption or secure handling mechanisms increases the likelihood of this type of exploitation, leaving sensitive information more vulnerable.
Affected products
-
- Version C0-0xStatusaffectedConstraints-
- Version C0-1xStatusaffectedConstraints-
- Version C2-xStatusaffectedConstraints-
- Version V3.90StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| AutomationDirect | CLICK Programmable Logic Controller | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
AutomationDirect recommends that users update CLICK PLUS and firmware to V3.90.
Weaknesses (1)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jan 22, 2026
Updated Jan 23, 2026
Reserved Dec 9, 2025
Link CVE-2025-67652
CISA Vulnrichment
Updated Jan 23, 2026