CVE-2025-13970

OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack due to the absence of proper CSRF validation. This issue allows an unauthenticated attacker to trick a logged-in administrator into visiting a maliciously crafted link, potentially enabling unauthorized modification of PLC settings or the upload of malicious programs which could lead to significant disruption or damage to connected systems.
Configurations

No configuration.

History

13 Dec 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-13 01:15

Updated : 2025-12-15 18:22


NVD link : CVE-2025-13970

Mitre link : CVE-2025-13970

CVE.ORG link : CVE-2025-13970


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)