CVE-2020-12042: OPTO22 Softpac Project

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system access.

Affected products

  • OPTO22 Softpac Project: up to and including 9.6

Published 2020-05-14. Last modified 2026-06-17.