CVE-2021-47770

Severity CVSS v4.0:
HIGH
Type:
CWE-94 Code Injection
Publication date:
21/01/2026
Last modified:
21/01/2026

Description

OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to inject malicious code through the hardware configuration interface. Attackers can upload a custom hardware layer with embedded reverse shell code that establishes a network connection to a specified IP and port, enabling remote command execution.