CVE-2021-47770
EUVD-2026-365521.01.2026, 18:16
OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to inject malicious code through the hardware configuration interface. Attackers can upload a custom hardware layer with embedded reverse shell code that establishes a network connection to a specified IP and port, enabling remote command execution.
Awaiting analysis
This vulnerability is currently awaiting analysis.