Nicholas TongAutomationDirect CLICK PLC (C0-10DD1E-D)
53 / 56
the PLC that never asks who's asking
Eleven lines of Python. That's the whole distance between my laptop and a machine designed to run a plant for twenty years. The script uses pymodbus, opens a TCP socket to port 502, and sends a single write-single-coil request addressed to Y001. The pilot lamp wired to that output, a 24 volt indicator pulled from a junk drawer, lights up green on the PLC sitting on a DIN rail by my monitor. Ten minutes of reading, one function call, and a real industrial controller did what the packet said.
My dad was standing behind me when it lit. He spent thirty years as a machinist by the ship channel, and he watched the lamp blink on and off twice before he asked the only question that matters about this entire field: "Nobody needed a password for that?" Nobody did. That's not a misconfiguration. That's the design.
the part everyone gets wrong
People treat OT like IT with older computers, and the comparison feels natural because there are cables and IP addresses on both sides. It's wrong at the foundation. On the IT side, security begins at authentication: who are you, prove it, then we'll talk. Modbus was born in 1979 as a protocol for controllers talking over serial wire to each other, in a world where touching the wire meant being in the room. It has no authentication and no encryption, and when it got carried over TCP around the turn of the millennium, none was bolted on. The Ethernet CLICK I bought does Modbus TCP and EtherNet/IP on one RJ45 port, and either protocol will happily take a write from any device that can reach it.
So the real security controls for a PLC were never going to be logins. They're network architecture and physical process. Who can reach the wire, and what does a write to that wire physically do. If you learn one thing from a $274 desk lab, it's that the access control list lives in the switch config and the consequence lives in the wiring, and the PLC's own security posture is somewhere behind both.
what the scan cycle actually does
A PLC is not a small computer running a program the way your laptop runs a browser. It runs a loop, and the loop is the whole machine: read every input, solve the logic, write every output, do the housekeeping, repeat. Milliseconds per pass. Modbus writes don't interrupt the loop; they land in the memory image and the next scan obeys them. There's no session to establish, no handshake beyond TCP itself, no record that anyone was ever there. My write arrived, the scan picked it up, and Y001 went high in the next output update, a few milliseconds later.
That's the mechanics, and it explains the failure mode people don't expect: a PLC does what the last packet said. Not what the engineer said last month, not what the ladder logic says on the printed drawing taped inside the panel door. The last packet. If a compromise writes new logic or just coils, the machine runs it faithfully, at scan rate, forever, because a PLC has no reason to distrust the network it sits on. The CLICK's programming software is a free download, which sounds generous until you realize it means anyone with the software and the wire can do what I did.
Costs, since I count in hours and dollars: the C0-10DD1E-D is $201 from AutomationDirect, the C0-01AC 24 volt power supply is $73, and that's the whole build, $274, kept under the line where I'd have to tell you this isn't a purchase recommendation. The supply is backordered until late November at the moment, so I'd point out any 24 VDC DIN supply works; mine came from the same junk drawer as the lamp. One I/O expansion module would push the total past $300, which is why the desk lab stays at two parts. The eleven lines of Python took ten minutes. Reading the CLICK communications manual took longer than building the thing.
where it breaks
The advisories read like a field's history compressed into one product page, and they're dated facts, not scares.
In 2021, CISA advisory ICSA-21-166-02 described an authentication bypass and cleartext passwords, fixed in firmware v3.00. The interesting part is the phrase: a PLC got a login screen, and the login screen got bypassed, which is what happens when you add IT-shaped controls to a device whose protocol never asked for them. In September 2025, ICSA-25-266-01 hit the CLICK PLUS line, and Nozomi Networks Labs' teardown found a hard-coded AES key and key generation seeded from a timestamp, the kind of crypto that looks like crypto and mostly isn't. Fixed in V3.80. Then in January 2026, ICSA-26-022-02, covering the whole C0 and C2 family including mine: passwords weakly encoded, and plaintext passwords stored in project files, fixed in V3.90.
I want to be careful here, because the lesson is not "AutomationDirect is bad." Every vendor in this space has advisories shaped like these, because the entire product category spent forty years assuming the network was trustworthy. The lesson is that security patches on a plant floor are not like security patches on my laptop. My desk PLC updated in twenty minutes while nothing was connected to it. A PLC running a pump skid updates during a shutdown somebody has to schedule and justify, so the fleet runs years on old firmware, which is exactly what the advisories assume.
what I'd do first
- Never point Modbus writes at anything you don't own. Read-only against infrastructure you don't control is still legally and ethically gray, so write nothing, not even once, not even harmlessly.
- Segment the controls network and put port 502 behind a firewall rule you can recite. The ACL is the authentication the protocol never had.
- In the lab, give the PLC an address that can't route to the internet and expect it to still get scanned, because everything gets scanned.
- Patch on the bench, not in production, and treat the vendor's compensating controls list as the actual plan for the fleet that can't be patched yet.
- Decide what the worst legitimate write in your process does, then design so a stranger with port 502 can't perform it. That's the control that matters. Everything else is a login screen in front of an open door.
The calipers came out that same afternoon, my dad's, the pair that lives in the fire safe, because I'd stripped the head off the DIN rail screw holding the CLICK and wanted to know by how much. He checked it, said "about a third gone," and then said the lamp trick was how real plants get hurt, slowly, by people with laptops. I've thought about that sentence every day since.
And the admission: I owned this PLC for three weeks before I wrote the eleven lines. I kept reading the Modbus specification instead, function codes and exception responses, promising myself I'd get to it. Reading about the machine is not the same as touching it. The lamp taught me more in one blink than the spec did in a month.
Nobody needed a password. Design like you know that.