CVE-2021-31630
HIGHOpenPLC Webserver v3 - Remote Code Execution via Hardware Layer Code Box
Title source: llmExploitation Summary
EIP tracks 12 public exploits for CVE-2021-31630. PoCs published by thewhiteh4t, Hunt3r0x, machevalia.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2021-31630, an authenticated remote code execution vulnerability in OpenPLC WebServer v3. The exploit uploads a malicious C payload to the target, compiles it, and executes a reverse shell.
Description
Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.
Exploits (12)
This repository contains a functional Python exploit for CVE-2021-31630, an authenticated remote code execution vulnerability in OpenPLC WebServer v3. The exploit uploads a malicious C payload to the target, compiles it, and executes a reverse shell.
This repository contains a functional exploit for CVE-2021-31630, targeting OpenPLC on the WifineticTwo Hack The Box machine. The exploit authenticates with provided credentials, uploads a malicious payload via a multipart form, and establishes a reverse shell.
This repository contains a functional Python exploit for CVE-2021-31630, an authenticated RCE vulnerability in OpenPLC v3. The exploit uploads a malicious custom hardware layer containing a reverse shell payload, compiles it, and triggers execution to achieve remote code execution.
The repository contains only a minimal README with a title and brief description, lacking any exploit code or technical details. It claims to be an exploit for CVE-2021-31630 but provides no functional implementation or analysis.
This repository contains a functional Python script that exploits CVE-2021-31630, a command injection vulnerability in OpenPLC Web Server v3. The exploit automates the process of uploading a malicious payload to the 'Hardware Layer Code Box' component, compiling it, and establishing a reverse shell.
The repository contains a functional exploit for CVE-2021-31630, a command injection vulnerability in OpenPLC v3's web server. The exploit leverages unsanitized input in the hardware layer code box to execute arbitrary commands, demonstrated via a reverse shell payload.
This repository contains a functional exploit for CVE-2021-31630, targeting OpenPLC_v3 WebServer. The exploit leverages a code injection vulnerability in the hardware layer customization feature to achieve remote command execution (RCE) by embedding malicious code in the `initCustomLayer()` function.
This repository contains a functional exploit for CVE-2021-31630, an authenticated RCE vulnerability in OpenPLC WebServer v3. The exploit authenticates, uploads a malicious C file with a reverse shell payload, compiles it, and executes it to achieve remote code execution.
This repository contains a functional exploit for CVE-2021-31630, an authenticated remote code execution vulnerability in OpenPLC WebServer v3. The exploit leverages command injection to upload and execute a malicious payload, resulting in a reverse shell.
This repository contains a functional exploit for CVE-2021-31630, targeting OpenPLC WebServer v3. The exploit authenticates, uploads a malicious program, and achieves remote code execution via a reverse shell.
This repository contains a functional exploit for CVE-2021-31630, an authenticated remote code execution vulnerability in OpenPLC WebServer v3. The exploit leverages command injection in the 'Hardware Layer Code Box' component to execute arbitrary code via a reverse shell.
This repository contains a functional Python exploit for CVE-2021-31630, targeting OpenPLC on the WifineticTwo HackTheBox machine. The exploit automates login, uploads a malicious payload to achieve remote code execution, and triggers a reverse shell.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H