An authorization bypass vulnerability has been discovered...
High severity
Unreviewed
Published
Sep 24, 2025
to the GitHub Advisory Database
•
Updated Sep 24, 2025
Description
Published by the National Vulnerability Database
Sep 23, 2025
Published to the GitHub Advisory Database
Sep 24, 2025
Last updated
Sep 24, 2025
An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Through the KOPR protocol utilized by the Remote PLC application, authenticated users with low-level access permissions can exploit this vulnerability to read and modify PLC variables beyond their intended authorization level.
References