Apache Plc4X · Plc4J · CVE-2026-102511
**Name of the Vulnerable Software and Affected Versions**
Apache PLC4X PLC4Go versions 0.11.0 through 0.9.9
Apache PLC4X PLC4J ADS and Modbus drivers versions 0.10.0 through 0.9.9
Apache PLC4X PLC4J EtherNet/IP driver versions 0.11.0 through 0.9.9
**Description**
Improper verification of the communication channel source in the ADS discovery of the Go implementation (PLC4Go) allows an attacker to send UDP datagrams to a discovering host to redirect subsequent connections to an arbitrary address. This occurs because the connection address is derived from the `AmsNetId` claimed in the response body instead of the actual source address of the datagram. Consequently, a spoofed response can insert an inventory entry pointing to any host, causing applications to send ADS sessions and route credentials to the attacker-controlled address.
Additionally, discovery listeners can be disabled via malformed datagrams:
- In PLC4Go ADS discovery, a short version block triggers a panic that terminates the listener.
- In PLC4J, the ADS and EtherNet/IP discoverers stop due to unhandled exceptions from malformed responses.
- The PLC4J Modbus discoverer may enter an infinite loop, consuming a CPU core, when receiving a partial response from a scanned host.
Exploitation requires the application to use the opt-in discovery API and act upon the discovered items.
**Recommendations**
Upgrade PLC4Go to version 1.0.0.
Upgrade PLC4J ADS and Modbus drivers to version 1.0.0.
Upgrade PLC4J EtherNet/IP driver to version 1.0.0.