Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-31156

Опубликовано: 13 мая 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path parameters passed via the command line. The user-controlled input parameters are directly passed to the underlying file operation functions (fopen/ifstream/ofstream) for file reading and writing. An attacker can exploit this vulnerability by constructing a malicious path to read arbitrary readable files.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:openplcproject:openplc_v3_firmware:2024-03-09:*:*:*:*:*:*:*
cpe:2.3:h:openplcproject:openplc_v3:-:*:*:*:*:*:*:*

EPSS

Процентиль: 31%
0.00387
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
github
3 месяца назад

A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path parameters passed via the command line. The user-controlled input parameters are directly passed to the underlying file operation functions (fopen/ifstream/ofstream) for file reading and writing. An attacker can exploit this vulnerability by constructing a malicious path to read arbitrary readable files.

CVSS3: 6.5
fstec
3 месяца назад

Уязвимость сценария glue_generator.cpp микропрограммного обеспечения программируемых логических контроллеров OpenPLC, позволяющая нарушителю читать и записывать произвольные файлы

EPSS

Процентиль: 31%
0.00387
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22