CVE-2026-28205 PUBLISHED

Initialization of a resource with an insecure default in OpenPLC_V3

Assigner: icscert
Reserved: 06.04.2026 Published: 09.04.2026 Updated: 09.04.2026

OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H
CVSS Score: 9.2

Product Status

Vendor OpenPLC_V3
Product OpenPLC_V3
Versions Default: unaffected
  • Version All versions is affected

Workarounds

OpenPLC_v3 is now considered to be end of life. Users are recommended to upgrade to OpenPLC Runtime v4 ( https://github.com/autonomy-logic/openplc-runtime ).

Credits

  • Shriyans Sudhi (ss0x00) from Rochester Institute of Technology (RIT) finder

References

Problem Types

  • CWE-1188 Initialization of a resource with an insecure default CWE