ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds an OpenPLC ScadaBR flaw to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2021-26829

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-26829
Cross-Site Scripting (XSS) in OpenPLC ScadaBR system_settings.shtm

OpenPLC ScadaBR, an open-source SCADA/HMI web application, contains a cross-site scripting flaw (CWE-79) in its system_settings.shtm settings page. An attacker can trigger it by getting a user's browser to load system_settings.shtm with malicious script injected into the request, which the application then renders without adequate sanitization. Successful exploitation executes attacker-supplied script in the victim's browser session, potentially hijacking the authenticated web session and performing actions such as changing settings or views as that user. Any organization running the OpenPLC ScadaBR web interface is affected, especially instances reachable from the internet or by untrusted users. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-11-28, indicating exploitation in the wild, and EPSS assigns a 48% probability of exploitation within 30 days (99th percentile); no public proof-of-concept is known and no CVSS score has been published.

Do: Apply mitigations per vendor instructions and update ScadaBR/OpenPLC to the latest available build, since the advisory does not specify a fixed version; federal agencies must meet the BOD 22-01 deadline or discontinue use if mitigations are unavailable. Restrict network access to the ScadaBR web interface so it is not directly internet-exposed, and review web-server logs for suspicious or script-bearing requests to system_settings.shtm. Prioritize patching on internet-facing instances given the KEV listing and elevated EPSS score.

5.448% KEV PoC
  • OpenPLC ScadaBR
nicheLikely hundreds to a few thousand ScadaBR instances worldwide (estimate; no published install base)
Full article343 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 01, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an OpenPLC ScadaBR flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an OpenPLC ScadaBR flaw, tracked as CVE-2021-26829  (CVSS score of 5.4), to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability is a cross-site scripting (XSS) flaw that impacts Windows and Linux versions via system_settings.shtm. The vulnerability impacts OpenPLC ScadaBR through 1.12.4 on Windows and OpenPLC ScadaBR through 0.9.1 on Linux.

In September 2025, the pro-Russian hacktivist group TwoNet attacked an ICS/OT honeypot operated by cybersecurity firm Forescout, believing it was a water treatment plant. Attackers used used default credentials to gain access to the target system, then created a “BARLATI” account, and exploited CVE-2021-26829 to deface the HMI login page and disable logs and alarms.

“The attacker next created a new user account named “BARLATI”. The first login with this account took place at 3:20 PM – about seven hours after the initial compromise. The last login occurred the following morning at 11:19 AM.” wrote Forescout. “During that window, the attacker carried out four defacement and disruption actions:

  • Defacement: Exploited CVE-2021-26829 to change the HMI login page description to: [<]script>alert("HACKED BY BARLATI, FUCK")</script>

triggering a pop-up alert with the expletive whenever the page was visited.”

They focused only on the web layer and didn’t escalate privileges. Active since January, TwoNet has evolved from DDoS to targeting industrial systems, doxxing, and offering RaaS, hack-for-hire, and initial access services, while claiming ties to CyberTroops and OverFlame.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by December 19, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185185/security/u-s-cisa-adds-an-openplc-scadabr-flaw-to-its-known-exploited-vulnerabilities-catalog.html