CVE-2021-26828
KEV PoC ×3moderateAuthenticated JSP File Upload RCE in OpenPLC ScadaBR (view_edit.shtm)
CISA: OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
OpenPLC ScadaBR contains an unrestricted file upload flaw (CWE-434) in its web interface that lets a remote, authenticated user upload arbitrary JSP files through view_edit.shtm. Once uploaded, the malicious JSP is executed by the application server, giving the attacker remote code execution on the host running ScadaBR. Because exploitation requires valid credentials, risk is highest in deployments where default, shared, or weak passwords are used, which is common in OT/SCADA environments. The flaw affects OpenPLC's ScadaBR SCADA/HMI software. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-03, confirming active exploitation in the wild, and EPSS puts its 30-day exploitation probability at 39.4% (99th percentile); no public PoC is known.
What to do: Update ScadaBR/OpenPLC to the latest vendor release per vendor guidance, as required by CISA's KEV listing and BOD 22-01 for federal agencies. Until patched, restrict access to the ScadaBR web interface (including view_edit.shtm) to trusted users and networks, enforce strong unique credentials since exploitation requires authentication, and check the ScadaBR webapps/upload directories and access logs for unexpected .jsp files or recent uploads.
| OpenPLC ScadaBR | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
- Affected
- OpenPLC ScadaBR
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- scadabr
- Products
- scadabr
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H