CRITICAL🇵🇱 Wersja polska

CVE-2026-28205

CVSS 9.2v4.0pub. 2026-04-09upd. 2026-04-28

OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API.

🤖 AI Analysis
How it works

The vulnerability results from improper resource initialization, which in its default state does not require authentication credentials. A network attacker, without needing to possess an account or any user interaction, can send requests to the OpenPLC V3 API and gain access to functions requiring authorization. The flaw affects both the firmware layer and OpenPLC V3 software, meaning that both hardware devices and software installations are vulnerable.

Impact

An attacker can bypass the authentication mechanism and gain unauthorized access to the OpenPLC V3 system, which in an industrial environment could lead to unauthorized data reading, modification of control logic, or disruption of the control system's availability.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references (CISA ICS Advisory ICSA-25-345-10). Additionally, it is recommended to isolate OpenPLC systems from public networks, restrict API access exclusively to trusted hosts, and verify and change default authentication configurations.

Who is affected

Openplcproject OpenPLC V3 Firmware and Openplcproject OpenPLC V3 — versions indicated in manufacturer references (CISA advisory ICSA-25-345-10)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Openplcproject Openplc V3

    HW
    Openplcproject
    all versions
  • Openplcproject Openplc V3 Firmware

    OS
    Openplcproject
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-35556CRITICAL9.2PL ✓same product

OpenPLC V3 — przechowywanie haseł w postaci jawnego tekstu (CWE-256)

CVE-2024-34026CRITICAL9.0PL ✓same product

Stack-based buffer overflow w OpenPLC V3 — RCE przez EtherNet/IP

CVE-2018-20818CRITICAL9.8PL ✓same product

Buffer overflow w OpenPLC V2/V3 — funkcja mapUnusedIO() w modbus.cpp

CVE-2026-35063HIGH8.7same product

OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated u...

CVE-2024-36981HIGH7.5same product

An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of Ope...