CVE-2021-31630
Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.
- Affected products
- Open Plc Webserver
- Openplcproject Openplc v3 Firmware
- All versions
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 27.1% (98th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2021-08-03
CVE-2021-31630 at NVD
9 known exploits for CVE-2021-31630
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Code Injection in Openplcproject Openplc_V3_Firmware
Exploit for Code Injection in Openplcproject Openplc_V3_Firmware
Exploit for Code Injection in Openplcproject Openplc_V3_Firmware
Exploit for Code Injection in Openplcproject Openplc_V3_Firmware
Exploit for Code Injection in Openplcproject Openplc_V3_Firmware
Exploit for Code Injection in Openplcproject Openplc_V3_Firmware
Exploit for Code Injection in Openplcproject Openplc_V3_Firmware
Exploit for Code Injection in Openplcproject Openplc_V3_Firmware
Exploit for Code Injection in Openplcproject Openplc_V3_Firmware