cve detail
CVE-2021-26828
naam
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
KEV
bekend misbruikt
EPSS
80%
percentiel
99%
vendor
OpenPLC
product
ScadaBR
toegevoegd aan KEV
03 dec 2025
due date
24 dec 2025
ransomware
Unknown
CWE
CWE-434
EPSS datum
12 mei 2026
aanbevolen actie
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
notities
This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/SCADA-LTS/Scada-LTS/pull/2174 ; https://nvd.nist.gov/vuln/detail/CVE-2021-26828