PT-2025-51034 · Unknown · Openplc V3

CVE-2025-13970

·

Published

2025-12-13

·

Updated

2025-12-18

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenPLC V3 (affected versions not specified)
Description The software is susceptible to a cross-site request forgery (CSRF) attack because of missing CSRF validation. An unauthenticated attacker can potentially trick a logged-in administrator into visiting a malicious link. This could allow unauthorized modification of PLC settings or the upload of malicious programs, potentially causing disruption or damage to connected systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13970

Affected Products

Openplc V3