CVE-2026-28205

CRITICAL

Initialization of a resource with an insecure default in OpenPLC_V3

Title source: cna
STIX 2.1

Description

OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API.

Scores

CVSS v3 9.8
EPSS 0.0008
EPSS Percentile 24.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1188
Status published
Products (2)
OpenPLC_V3/OpenPLC_V3 All versions
openplcproject/openplc_v3_firmware
Published Apr 09, 2026
Tracked Since Apr 10, 2026