CVE Explorer
CVE-2026-28205
OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"OpenPLC_V3","vendor":"OpenPLC_V3","versions":[{"status":"affected","version":"All versions"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8a97eb491e0463e0d305cada0979fa53dd952ccc3f4c7a26f353c22bcf12a580 · sha256:40bc9216326095d5… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":9.2,"baseSeverity":"CRITICAL","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"LOW","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImp…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8a97eb491e0463e0d305cada0979fa53dd952ccc3f4c7a26f353c22bcf12a580 · sha256:40bc9216326095d5… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-1188","description":"CWE-1188 Initialization of a resource with an insecure default","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8a97eb491e0463e0d305cada0979fa53dd952ccc3f4c7a26f353c22bcf12a580 · sha256:40bc9216326095d5… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["government-resource"],"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-10"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8a97eb491e0463e0d305cada0979fa53dd952ccc3f4c7a26f353c22bcf12a580 · sha256:40bc9216326095d5… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.