CVE-2021-31630 is a command injection vulnerability in Open PLC Webserver v3. The vulnerability exists in the 'Hardware Layer Code Box' component accessible via the '/hardware' page, where user-supplied input is not properly sanitized, allowing remote attackers to inject and execute arbitrary commands on the underlying system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains the OpenPLC v3 runtime and associated tools, as well as proof-of-concept exploit code for CVE-2021-31630, a critical authenticated code/command injection vulnerability in the OpenPLC WebServer. The main exploit scripts are 'cve_2021_31630.py' and 'exploit.py', both written in Python. These scripts automate the exploitation process by authenticating to the web interface, uploading a malicious C payload as custom hardware layer code, compiling it, and starting the PLC to trigger execution. The payload opens a reverse shell to the attacker's machine, granting remote command execution as the webserver user. The exploit requires valid credentials and network access to the OpenPLC web interface. The repository also includes build scripts, documentation, and source code for the OpenPLC runtime and supporting libraries. The exploit is operational and demonstrates a real-world attack chain against OpenPLC v3 WebServer.
This repository provides a working exploit for CVE-2021-31630, a remote code execution vulnerability in OpenPLC_v3 WebServer. The repository contains two files: a detailed README.md (with manual exploitation steps, code snippets, and screenshots) and exp.py, a Python script that automates the exploitation process. The exploit works by authenticating to the OpenPLC web interface, uploading a crafted .st project file, injecting malicious C code into the hardware layer (which executes arbitrary system commands via the system() call), compiling the project, and finally triggering execution by starting the PLC. The payload can be any system command, including those that establish a reverse shell to an attacker-controlled host. The Python script interacts with several HTTP endpoints on the target (such as /login, /upload-program, /hardware, /compile-program, /start_plc) to automate the attack chain. The README also demonstrates how to manually exploit the vulnerability, including how to craft and inject a reverse shell payload. The exploit is operational and provides blind command execution or a reverse shell, depending on the payload. The main attack vector is network-based, requiring access to the OpenPLC web interface and valid credentials. The repository is well-documented and provides both automated and manual exploitation methods.
This repository contains a Python exploit (exploit.py) for CVE-2021-31630, targeting OpenPLC Webserver v3. The exploit leverages an authenticated command injection vulnerability in the 'Hardware Layer Code Box' on the /hardware page. The attacker must provide valid credentials to the web interface. The exploit workflow is as follows: (1) log in to the webserver to obtain a session, (2) upload a benign structured text program, (3) upload malicious C code to the hardware layer that initiates a reverse shell to the attacker's machine, (4) compile the program, and (5) start the PLC to trigger code execution. The payload is a C reverse shell that connects back to the attacker's specified IP and port. The exploit interacts with several HTTP endpoints on the target, including /login, /upload-program, /hardware, /compile-program, and /start_plc. The repository is structured with a single exploit script, a README describing usage and context, and a .gitignore file. The exploit is operational and provides a working reverse shell if the target is vulnerable and credentials are known.
This repository contains a Python exploit script (breakerplc.py) and a README.md for CVE-2021-31630, a command injection vulnerability in OpenPLC Web Server v3. The exploit automates the process of authenticating to the OpenPLC web interface, uploading a malicious C payload via the '/hardware' endpoint, compiling it, and starting the PLC to trigger a reverse shell connection to the attacker's machine. The script also manages cleanup by stopping the PLC and restoring the original hardware configuration. The only code file is breakerplc.py, which is the main entry point and orchestrates the entire attack chain. The exploit requires valid credentials (default: openplc/openplc) and network access to the target. The payload is a C reverse shell that connects back to the attacker's specified IP and port. The repository is operational and provides a working exploit for remote code execution on vulnerable OpenPLC Web Server v3 instances.
This repository provides a working exploit for CVE-2021-31630, an authenticated remote code execution vulnerability in OpenPLC v3. The main exploit script (OpenPLC_CVE_2021_31630.py) is a Python 3.13+ tool that automates the attack: it logs in to the OpenPLC web server (default credentials: openplc:openplc), uploads a malicious C payload as a custom hardware layer, triggers compilation, and starts the PLC to execute the payload. The payload is a reverse shell that connects back to the attacker's specified IP and port, granting remote shell access on the target system. The script also includes cleanup routines to stop the PLC and restore the original hardware layer. The repository also includes two Nuclei detection templates: one for checking default credentials and another for passively detecting the vulnerability by uploading a harmless payload and checking for successful compilation, without triggering code execution. These templates allow for safe detection and credential auditing of OpenPLC instances. Endpoints targeted by the exploit include /login, /hardware, /compile-program, /start_plc, /stop_plc, and /restore_custom_hardware. The attack vector is network-based, requiring access to the OpenPLC web interface. The exploit is operational, providing a real reverse shell payload, and is suitable for authorized penetration testing or red teaming against vulnerable OpenPLC v3 deployments.
This repository contains a Python proof-of-concept exploit for CVE-2021-31630, targeting OpenPLC WebServer v3. The exploit requires valid credentials (default: openplc/openplc) and interacts with the web server's HTTP API to achieve authenticated remote code execution. The main script, cve_2021_31630.py, performs the following steps: checks service health, logs in, restores the default program, uploads a C-based reverse shell payload to the /hardware endpoint, triggers compilation, starts the PLC to execute the payload, and finally cleans up by restoring the default hardware configuration. The payload is a non-blocking C reverse shell that connects back to the attacker's specified host and port, providing remote shell access. The repository is structured with a single exploit script and a README detailing usage and features. The attack vector is network-based, exploiting authenticated access to the OpenPLC WebServer's management endpoints.
This repository contains a proof-of-concept exploit for CVE-2021-31630, targeting the OpenPLC service running on the WifineticTwo box (Hack The Box). The exploit consists of a single Python script (exploit.py) and a README.md with usage instructions. The script authenticates to the OpenPLC web interface using provided credentials, uploads a malicious C payload via a multipart/form-data POST request, triggers compilation and execution of the payload, and ultimately establishes a reverse shell from the target to the attacker's machine. The exploit is operational, requiring the attacker to provide a listening IP and port, as well as valid OpenPLC credentials. The main attack vector is network-based, exploiting the OpenPLC web interface at http://wifinetictwo.htb:8080. The payload is a C reverse shell embedded in the upload request. The repository is well-structured for its purpose, with clear instructions and a single exploit script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.