CVE-2025-13970: OpenPLC v3
High severity, CVSS 8.0. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack due to the absence of proper CSRF validation. This issue allows an unauthenticated attacker to trick a logged-in administrator into visiting a maliciously crafted link, potentially enabling unauthorized modification of PLC settings or the upload of malicious programs which could lead to significant disruption or damage to connected systems.
Affected products
- OpenPLC v3 OpenPLC v3
Published 2025-12-13. Last modified 2026-06-17.