CVE-2025-62498

HIGH

Productivity Suite <4.4.1.19 - Path Traversal

Title source: llm
STIX 2.1

Description

A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker who can tamper with a productivity project to execute arbitrary code on the machine where the project is opened.

Scores

CVSS v3 8.8
EPSS 0.0006
EPSS Percentile 17.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-23
Status published
Products (8)
AutomationDirect/Productivity 1000 P1-540 CPU < SW v4.4.1.19
AutomationDirect/Productivity 1000 P1-550 CPU < SW v4.4.1.19
AutomationDirect/Productivity 2000 P2-550 CPU < SW v4.4.1.19
AutomationDirect/Productivity 2000 P2-622 CPU < SW v4.4.1.19
AutomationDirect/Productivity 3000 P3-530 CPU < SW v4.4.1.19
AutomationDirect/Productivity 3000 P3-550E CPU < SW V4.2.1.9
AutomationDirect/Productivity 3000 P3-622 CPU < SW V4.2.1.9
AutomationDirect/Productivity Suite < SW V4.2.1.9
Published Oct 23, 2025
Tracked Since Feb 18, 2026