CVE-2021-26828
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 December 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 39.36% probability · 99th percentile
- CISA KEV
- Listed 3 December 2025 · due 24 December 2025
- Weakness
- CWE-434
- Affected
- scadabr/scadabr
- Source
- cve@mitre.org
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/SCADA-LTS/Scada-LTS/pull/2174 ; https://nvd.nist.gov/vuln/detail/CVE-2021-26828
References
- http://forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3615/4Broken Link, Exploit, Vendor Advisory
- http://packetstormsecurity.com/files/162564/ScadaBR-1.0-1.1CE-Linux-Shell-Upload.htmlExploit, Third Party Advisory
- https://youtu.be/k1teIStQr1AExploit, Third Party Advisory
- http://forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3615/4Broken Link, Exploit, Vendor Advisory
- http://packetstormsecurity.com/files/162564/ScadaBR-1.0-1.1CE-Linux-Shell-Upload.htmlExploit, Third Party Advisory
- https://youtu.be/k1teIStQr1AExploit, Third Party Advisory
- https://github.com/SCADA-LTS/Scada-LTS/pull/2174Issue Tracking, Patch
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26828US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.