CVE-2025-13970
HIGHOpenPLC_V3 - CSRF
Title source: llmDescription
OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack due to the absence of proper CSRF validation. This issue allows an unauthenticated attacker to trick a logged-in administrator into visiting a maliciously crafted link, potentially enabling unauthorized modification of PLC settings or the upload of malicious programs which could lead to significant disruption or damage to connected systems.
Scores
CVSS v3
8.0
EPSS
0.0002
EPSS Percentile
4.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:H
Classification
CWE
CWE-352
Status
draft
Timeline
Published
Dec 13, 2025
Tracked Since
Feb 18, 2026