CVE-2025-36535

CRITICAL

AutomationDirect MB-Gateway Web Server - Unauthenticated Configuration Access

Title source: manual
STIX 2.1

Description

The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the environment and exposed functionality.

Scores

CVSS v3 10.0
EPSS 0.0097
EPSS Percentile 57.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
AutomationDirect/MB-Gateway All
Published May 21, 2025
Tracked Since Feb 18, 2026