CVE-2026-28205
Received
Received - Intake
Insecure Default Initialization in OpenPLC_V3 Enables Authentication Bypass
Publication date: 2026-04-09
Last updated on: 2026-04-28
Assigner: ICS-CERT
Description
Description
OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| openplcproject | openplc_v3_firmware | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1188 | The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure. |