Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23485 | /edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then publicly accessible under the /static URI. |
Tue, 05 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openplcproject
Openplcproject openplc Openplcproject openplc V3 |
|
| Vendors & Products |
Openplcproject
Openplcproject openplc Openplcproject openplc V3 |
Mon, 04 Aug 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 04 Aug 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | /edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then publicly accessible under the /static URI. | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-04T16:45:21.796Z
Reserved: 2025-08-04T00:00:00.000Z
Link: CVE-2025-54962
Updated: 2025-08-04T16:45:16.815Z
Status : Deferred
Published: 2025-08-04T02:15:27.153
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-54962
No data.
OpenCVE Enrichment
Updated: 2025-08-05T21:23:04Z
EUVD