CVE-2025-13970 - OpenPLC_V3 Cross-Site Request Forgery

CVE-2025-13970 - OpenPLC_V3 Cross-Site Request Forgery

CVE ID : CVE-2025-13970 Published : Dec. 13, 2025, 1:15 a.m. | 59 minutes ago Description : OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack due to the absence of proper CSRF validation. This issue allows an unauthenticated attacker to trick a logged-in administrator into visiting a maliciously crafted link, potentially enabling unauthorized modification of PLC settings or the upload of malicious programs which could lead to significant disruption or damage to connected systems. Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Dec. 13, 2025
Impact: CSRF

Source: Telegram CVE Monitor