CVE-2021-34605
HIGHXINJE XD/E Series PLC Program Tool < 3.5.1 - Arbitrary File Write via Zip Slip
Title source: llmDescription
A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by initiating an upload program request from an infected Xinje PLC. This can result in remote code execution, information disclosure and denial of service of the system running the XINJE XD/E Series PLC Program Tool.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://claroty.com/2022/05/11/blog-research-from-project-file-to-code-execution-exploiting-vulnerabilities-in-xinje-plc-program-tool/
Scores
CVSS v3
7.3
EPSS
0.0233
EPSS Percentile
81.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-23
Status
published
Products (1)
xinje/xd\/e_series_plc_program_tool
< 3.5.1
Published
May 11, 2022
Tracked Since
Feb 18, 2026