← Vulnerability feed

Vulnerability record · CVE-2021-31630 · published 3 August 2021

CVE-2021-31630: Openplcproject openplc v3 firmware code injection vulnerability

Openplcproject · Openplc V3 Firmware

Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.

8.8 CVSS 3.1 High EPSS 27% · top 2.0% CWE-94 · Code injection
8.8CVSS 3.1 base score, v2 9.0
27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-31630 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-34026Openplcproject openplc v3 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b454…EPSS 2.4%9.8CVE-2018-20818Openplcproject openplc v2 firmware memory buffer overflow vulnerabilityA buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It occurs in the modbus.cpp mapU…EPSS 1.5%9.2CVE-2026-35556Openplcproject openplc v3 firmware vulnerabilityOpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive…EPSS 0.40%9.2CVE-2026-28205Openplcproject openplc v3 firmware insecure default initialization vulnerabilityOpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to th…EPSS 0.67%8.7CVE-2026-35063Openplcproject openplc v3 firmware missing authorization vulnerabilityOpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other…EPSS 0.43%7.5CVE-2024-36981Openplcproject openplc v3 firmware out-of-bounds read vulnerabilityAn out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298…EPSS 1.0%7.5CVE-2024-39589Openplcproject openplc v3 firmware vulnerabilityMultiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7…EPSS 1.0%7.5CVE-2024-39590Openplcproject openplc v3 firmware vulnerabilityMultiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2021-31630), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.