CVE-2021-31630
HIGHOpenplcproject Openplc V3 Firmware - Code Injection
Title source: ruleDescription
Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.
Exploits (12)
nomisec
WORKING POC
3 stars
by machevalia · poc
https://github.com/machevalia/OpenPLC-CVE-2021-31630-RCE
nomisec
WORKING POC
by manuelsantosiglesias · poc
https://github.com/manuelsantosiglesias/CVE-2021-31630
nomisec
WORKING POC
by mind2hex · poc
https://github.com/mind2hex/CVE-2021-31630-OpenPLC-3-Authenticated-RCE
nomisec
WORKING POC
by behindsecurity · poc
https://github.com/behindsecurity/htb-wifinetictwo-exploit
Scores
CVSS v3
8.8
EPSS
0.8494
EPSS Percentile
99.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (1)
openplcproject/openplc_v3_firmware
Published
Aug 03, 2021
Tracked Since
Feb 18, 2026