CVE-2018-20818: Openplcproject OpenPLC v2 Firmware

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It occurs in the modbus.cpp mapUnusedIO() function, which can cause a runtime crash of the PLC or possibly have unspecified other impact.

Affected products

Published 2019-04-22. Last modified 2026-06-17.