PT-2025-31796 · Unknown · Openplc Runtime

Eyodav

·

Published

2025-08-04

·

Updated

2025-08-04

·

CVE-2025-54962

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenPLC Runtime versions 3 through 9cd8f1b
Description An authenticated user can upload arbitrary files, such as .html or .svg, through the /edit-user endpoint in the webserver. These uploaded files are then publicly accessible under the /static URI.
Recommendations Restrict access to the /edit-user endpoint to prevent unauthorized file uploads. Disable or remove the ability to upload files through the /edit-user endpoint.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-54962

Affected Products

Openplc Runtime