Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

AutomationDirect — Vulnerabilities & Security Advisories 55

Browse all 55 CVE security advisories affecting AutomationDirect. AI-powered Chinese analysis, POCs, and references for each vulnerability.

AutomationDirect operates as a provider of industrial automation components, including programmable logic controllers, human-machine interfaces, and motion control systems, primarily serving manufacturing and process industries. Security assessments have identified forty-nine Common Vulnerabilities and Exposures (CVEs) associated with its product ecosystem, indicating a significant historical attack surface. The majority of these vulnerabilities stem from insecure default configurations, improper access control mechanisms, and cross-site scripting flaws within web-based management interfaces. While remote code execution incidents are less frequent, privilege escalation bugs have allowed unauthorized users to gain administrative access to critical control systems. Notably, the company has faced scrutiny regarding delayed patch cycles for legacy hardware, which remains widely deployed in operational technology environments. These findings highlight persistent challenges in securing embedded industrial devices, where maintaining backward compatibility often conflicts with implementing robust, modern security protocols.

CVE ID Title CVSS Severity Published
CVE-2026-61378 AutomationDirect Productivity Suite Divide By Zero — Productivity Suite CWE-369 5.5 Medium 2026-07-16
CVE-2026-60073 AutomationDirect Productivity Suite Out-of-bounds Read — Productivity Suite CWE-125 5.9 Medium 2026-07-16
CVE-2026-57896 AutomationDirect Productivity Suite Out-of-bounds Read — Productivity Suite CWE-125 6.1 Medium 2026-07-16
CVE-2026-60140 AutomationDirect Productivity Suite Out-of-bounds Read — Productivity Suite CWE-125 6.1 Medium 2026-07-16
CVE-2026-61389 AutomationDirect Productivity Suite Out-of-bounds Write — Productivity Suite CWE-787 7.0 High 2026-07-16
CVE-2026-60063 AutomationDirect Productivity Suite Out-of-bounds Write — Productivity Suite CWE-787 7.0 High 2026-07-16
CVE-2025-25051 AutomationDirect CLICK Programmable Logic Controller Plaintext Storage of a Password — CLICK Programmable Logic Controller CWE-256 6.1 Medium 2026-01-22
CVE-2025-67652 AutomationDirect CLICK Programmable Logic Controller Weak Encoding for Password — CLICK Programmable Logic Controller CWE-261 6.1 Medium 2026-01-22
CVE-2025-60023 AutomationDirect Productivity Suite Relative Path Traversal — Productivity Suite CWE-23 4.0 Medium 2025-10-23
CVE-2025-59776 AutomationDirect Productivity Suite Relative Path Traversal — Productivity Suite CWE-23 4.0 Medium 2025-10-23
CVE-2025-58429 AutomationDirect Productivity Suite Relative Path Traversal — Productivity Suite CWE-23 7.5 High 2025-10-23
CVE-2025-58078 AutomationDirect Productivity Suite Relative Path Traversal — Productivity Suite CWE-23 7.5 High 2025-10-23
CVE-2025-58456 AutomationDirect Productivity Suite Relative Path Traversal — Productivity Suite CWE-23 6.8 Medium 2025-10-23
CVE-2025-61934 AutomationDirect Productivity Suite Binding to an Unrestricted IP Address CWE-1327 — Productivity Suite CWE-1327 10.0 Critical 2025-10-23
CVE-2025-62688 AutomationDirect Productivity Suite Incorrect Permission Assignment for Critical Resource — Productivity Suite CWE-732 7.1 High 2025-10-23
CVE-2025-61977 AutomationDirect Productivity Suite Weak Password Recovery Mechanism for Forgotten Password — Productivity Suite CWE-640 7.0 High 2025-10-23
CVE-2025-62498 AutomationDirect Productivity Suite Relative Path Traversal — Productivity Suite CWE-23 8.8 High 2025-10-23
CVE-2025-57882 AutomationDirect CLICK PLUS Improper Resource Shutdown or Release — CLICK PLUS C0-0x CPU firmware CWE-404 5.9 Medium 2025-09-23
CVE-2025-55038 AutomationDirect CLICK PLUS Missing Authorization — CLICK PLUS C0-0x CPU firmware CWE-862 6.8 Medium 2025-09-23
CVE-2025-58473 AutomationDirect CLICK PLUS Improper Resource Shutdown or Release — CLICK PLUS C0-0x CPU firmware CWE-404 5.9 Medium 2025-09-23
CVE-2025-55069 AutomationDirect CLICK PLUS Predictable Seed in Pseudo-Random Number Generator — CLICK PLUS C0-0x CPU firmware CWE-337 8.3 High 2025-09-23
CVE-2025-59484 AutomationDirect CLICK PLUS Use of a Broken or Risky Cryptographic Algorithm — CLICK PLUS C0-0x CPU firmware CWE-327 8.3 High 2025-09-23
CVE-2025-58069 AutomationDirect CLICK PLUS Use of Hard-coded Cryptographic Key — CLICK PLUS C0-0x CPU firmware CWE-321 5.3 Medium 2025-09-23
CVE-2025-54855 AutomationDirect CLICK PLUS Cleartext Storage of Sensitive Information — CLICK PLUS C0-0x CPU firmware CWE-312 4.2 Medium 2025-09-23
CVE-2025-36535 AutomationDirect MB-Gateway Missing Authentication for Critical Function — MB-Gateway CWE-306 10.0 Critical 2025-05-21
CVE-2025-0960 AutomationDirect C-more EA9 HMI Classic Buffer Overflow — C-more EA9 HMI EA9-T6CL CWE-120 9.8 Critical 2025-02-04
CVE-2024-11611 AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability — C-More EA9 CWE-119 7.8 - 2025-01-30
CVE-2024-11610 AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability — C-More EA9 CWE-119 7.8 - 2025-01-30
CVE-2024-11609 AutomationDirect C-More EA9 EAP9 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability — C-More EA9 CWE-121 7.8 - 2025-01-30
CVE-2024-45368 AutomationDirect DirectLogic H2-DM1E Session Fixation — DirectLogic H2-DM1E CWE-384 8.8 High 2024-09-13

This page lists every published CVE security advisory associated with AutomationDirect. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.