Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw Allows Remote Hacking of AutomationDirect Industrial Gateway

Critical Flaw Allows Remote Hacking of AutomationDirect Industrial Gateway

Posted on May 21, 2025May 21, 2025 By CWS

MB-Gateway gadgets made by industrial automation agency AutomationDirect are uncovered to distant assaults — together with immediately from the web — because of a essential vulnerability.

The existence of the vulnerability was disclosed on Tuesday by the cybersecurity company CISA, which famous in its advisory that the susceptible Modbus gateway product is used worldwide, together with in essential infrastructure. 

CISA described the vulnerability, which is tracked as CVE-2025-36535 and has a CVSS rating of 10, as a lacking authentication problem within the product’s embedded webserver, doubtlessly permitting unrestricted distant entry.

The company famous that the product’s {hardware} limitations stop the implementation of a correct entry management replace, and AutomationDirect has suggested customers to switch the MB-Gateway product with the EKI-1221-CE gateway.

Souvik Kandar, the Microsec researcher who found it, instructed SecurityWeek that the vulnerability may be exploited remotely from the web and there are over 100 web-exposed gadgets which may be impacted.

“The difficulty stems from a scarcity of authentication on the gadget’s embedded net interface. Anybody with web entry can attain the configuration panel with none credentials,” Kandar defined. 

“The uncovered interface leaks delicate gadget parameters comparable to inner IPs, firmware variations, Modbus configuration, and serial communication settings,” he added.

In accordance with the researcher, exploitation of the vulnerability can have a essential influence in some industrial environments. Commercial. Scroll to proceed studying.

An attacker might remotely modify gadget configurations, disrupt or manipulate Modbus communications between programs, get hold of detailed community and system info for lateral motion, and in sure configurations (relying on how the gateway is built-in and what capabilities are uncovered) an attacker might have the ability to execute arbitrary code.

Associated: As much as 25% of Web-Uncovered ICS Are Honeypots

Associated: Important Vulnerabilities Present in Planet Know-how Industrial Networking Merchandise

Associated: Lantronix System Utilized in Important Infrastructure Exposes Programs to Distant Hacking

Security Week News Tags:AutomationDirect, Critical, Flaw, Gateway, Hacking, Industrial, Remote

Post navigation

Previous Post: Coinbase Says Rogue Contractor Data Breach Affects 69,461 Users
Next Post: Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics

Related Posts

VerifTools Fake ID Operation Dismantled by Law Enforcement VerifTools Fake ID Operation Dismantled by Law Enforcement Security Week News
Firefox 145 and Chrome 142 Patch High-Severity Flaws in Latest Releases Firefox 145 and Chrome 142 Patch High-Severity Flaws in Latest Releases Security Week News
Adobe Patches Big Batch of Critical-Severity Software Flaws Adobe Patches Big Batch of Critical-Severity Software Flaws Security Week News
Plex Urges Password Resets Following Data Breach Plex Urges Password Resets Following Data Breach Security Week News
Panera Bread Data Breach: 5.1 Million Records Exposed Panera Bread Data Breach: 5.1 Million Records Exposed Security Week News
Coyote Banking Trojan First to Abuse Microsoft UIA Coyote Banking Trojan First to Abuse Microsoft UIA Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News