CVE-2021-31630

HIGH

Openplcproject Openplc V3 Firmware - Code Injection

Title source: rule

Description

Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.

Exploits (12)

nomisec WORKING POC 21 stars
by thewhiteh4t · poc
https://github.com/thewhiteh4t/cve-2021-31630
nomisec WORKING POC 9 stars
by Hunt3r0x · poc
https://github.com/Hunt3r0x/CVE-2021-31630-HTB
nomisec WORKING POC 3 stars
by machevalia · poc
https://github.com/machevalia/OpenPLC-CVE-2021-31630-RCE
nomisec STUB 2 stars
by hev0x · poc
https://github.com/hev0x/CVE-2021-31630-OpenPLC_RCE
nomisec WORKING POC 1 stars
by adibna · poc
https://github.com/adibna/cve-2021-31630
nomisec WORKING POC
by tranquac · poc
https://github.com/tranquac/OpenPLC_v3
nomisec WORKING POC
by UserB1ank · poc
https://github.com/UserB1ank/CVE-2021-31630
nomisec WORKING POC
by FlojBoj · poc
https://github.com/FlojBoj/CVE-2021-31630
nomisec WORKING POC
by manuelsantosiglesias · poc
https://github.com/manuelsantosiglesias/CVE-2021-31630
nomisec WORKING POC
by junnythemarksman · poc
https://github.com/junnythemarksman/CVE-2021-31630
nomisec WORKING POC
by mind2hex · poc
https://github.com/mind2hex/CVE-2021-31630-OpenPLC-3-Authenticated-RCE
nomisec WORKING POC
by behindsecurity · poc
https://github.com/behindsecurity/htb-wifinetictwo-exploit

Scores

CVSS v3 8.8
EPSS 0.8494
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
openplcproject/openplc_v3_firmware
Published Aug 03, 2021
Tracked Since Feb 18, 2026