OpenPLC_V3 is affected by a plaintext password storage vulnerability (CVE-2026-35556) that enables attackers to retrieve stored credentials and access sensitive system information. The vulnerability has a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction, indicating significant risk potential. The exploit is network-accessible, straightforward to execute, and impacts confidentiality severely, though integrity and availability are not affected. Currently, this vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and shows minimal exploitation activity, with an EPSS score of 0.00037 indicating low real-world exploitation likelihood at this time. Organizations running OpenPLC_V3 should prioritize patching efforts given the high severity rating and direct path to credential compromise, though immediate exploitation risk appears limited based on available threat intelligence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:openplcproject:openplc_v3_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.