Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-61934

34
FAUCET Score

CVE-2025-61934 is a critical binding to an unrestricted IP address vulnerability in Productivity Suite software version v4.4.1.19. This flaw allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator, enabling arbitrary file and folder operations (read, write, delete) on the target machine. With a CVSS score of 10.0 (CRITICAL) and a FAUCET Risk Score of 95/100, the vulnerability is easily exploitable over the network with low attack complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion, indicating awareness among security researchers.

Impacted Technologies

VendorProductVersion(s)CPE
AutomationDirectProductivity 1000 P1-540 CPU
>= 0, < SW v4.4.1.19CNA affecteddefault unaffected
AutomationDirectProductivity 1000 P1-550 CPU
>= 0, <= SW v4.4.1.19CNA affecteddefault unaffected
AutomationDirectProductivity 2000 P2-550 CPU
>= 0, <= SW v4.4.1.19CNA affecteddefault unaffected
AutomationDirectProductivity 2000 P2-622 CPU
>= 0, <= SW v4.4.1.19CNA affecteddefault unaffected
AutomationDirectProductivity 3000 P3-530 CPU
>= 0, <= SW v4.4.1.19CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.62%
Probability of exploitation in next 30 days
EPSS Percentile
46.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0062 is in the 27th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-296-01.json
support.automationdirect.com / docs/securityconsiderations.pdf
automationdirect.com / support/software-downloads
cisa.gov / news-events/ics-advisories/icsa-25-296-01