PT-2025-51034 · Unknown · Openplc V3

Published

2025-12-13

·

Updated

2025-12-18

·

CVE-2025-13970

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenPLC V3 (affected versions not specified)
Description The software is susceptible to a cross-site request forgery (CSRF) attack because of missing CSRF validation. An unauthenticated attacker can potentially trick a logged-in administrator into visiting a malicious link. This could allow unauthorized modification of PLC settings or the upload of malicious programs, potentially causing disruption or damage to connected systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-13970

Affected Products

Openplc V3