« Volver al listado

Openplc

Openplc V3: vulnerabilidades y CVE

Openplc V3 tiene 4 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE4
Últimos 12 meses2
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-11826Alta (8.7)0.75%—18 jul 2026
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a caller-supplied buffer with no size parameter and…
CVE-2025-13970Alta (7)0.29%—13 dic 2025
OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack due to the absence of proper CSRF validation. This issue allows an unauthenticated attacker to trick a logged-in administrator into visiting a…
CVE-2025-54811Media (6.1)0.21%—1 oct 2025
OpenPLC_V3 has a vulnerability in the enipThread function that occurs due to the lack of a return value. This leads to a crash when the server loop ends and execution hits an illegal ud2 instruction. This issue can be…
CVE-2025-1066Crítica (9.8)0.46%—6 feb 2025
OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campaigns.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1185 Browser Session Hijacking1
  2. T1190 Exploit Public-Facing Application1
  3. T1203 Exploitation for Client Execution1
  4. T1210 Exploitation of Remote Services1
  5. T1499.004 Application or System Exploitation1
  6. T1505.003 Web Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Openplc