ZeroHour

CVE-2021-26828

KEV PoC ×3moderate

Authenticated JSP File Upload RCE in OpenPLC ScadaBR (view_edit.shtm)

CISA: OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability

CVSS 3.1
8.8 high
EPSS
39%p99
Published
()
KEV added
AI analysis

OpenPLC ScadaBR contains an unrestricted file upload flaw (CWE-434) in its web interface that lets a remote, authenticated user upload arbitrary JSP files through view_edit.shtm. Once uploaded, the malicious JSP is executed by the application server, giving the attacker remote code execution on the host running ScadaBR. Because exploitation requires valid credentials, risk is highest in deployments where default, shared, or weak passwords are used, which is common in OT/SCADA environments. The flaw affects OpenPLC's ScadaBR SCADA/HMI software. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-03, confirming active exploitation in the wild, and EPSS puts its 30-day exploitation probability at 39.4% (99th percentile); no public PoC is known.

What to do: Update ScadaBR/OpenPLC to the latest vendor release per vendor guidance, as required by CISA's KEV listing and BOD 22-01 for federal agencies. Until patched, restrict access to the ScadaBR web interface (including view_edit.shtm) to trusted users and networks, enforce strong unique credentials since exploitation requires authentication, and check the ScadaBR webapps/upload directories and access logs for unexpected .jsp files or recent uploads.

Affected
OpenPLC ScadaBR
Estimated exposure
moderate~1,000-3,000 internet-exposed ScadaBR instances (rough order-of-magnitude estimate) — Public internet scans historically find only a few thousand exposed ScadaBR hosts, with deployments concentrated in Brazil, so the plausible affected population of exposed systems is in the low thousands; total authenticated-user exposure…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

CISA Known Exploited Vulnerability
Affected
OpenPLC ScadaBR
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
scadabr
Products
scadabr
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news