CVE-2025-1066: Malicious File Upload
Published Feb 5, 2025
·Updated
OpenPLCV3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campaigns.
Affected Software
1 affected component
OpenPLC OpenPLC V3
Event History
Feb 5, 2025
CVE Published
via MITRE·11:39 PM
Data Sourced
via MITRE·11:39 PM
DescriptionWeakness
Feb 6, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-1066?
CVE-2025-1066 has been classified as a high-severity vulnerability due to its potential for arbitrary file upload leading to further exploitation.
2
How do I fix CVE-2025-1066?
To fix CVE-2025-1066, update OpenPLC V3 to the latest version where this vulnerability has been patched.
3
What types of attacks can CVE-2025-1066 facilitate?
CVE-2025-1066 can facilitate malvertising and phishing campaigns due to the ability to upload arbitrary files.
4
Which versions of OpenPLC are affected by CVE-2025-1066?
CVE-2025-1066 affects all versions of OpenPLC V3 prior to the patch release addressing the vulnerability.
5
Is there a workaround for CVE-2025-1066?
A temporary workaround for CVE-2025-1066 is to restrict file upload permissions and monitor for suspicious activity until the vulnerability is resolved.