High severity8.8CISA KEVNVD Advisory· Published Jun 11, 2021· Updated Jun 17, 2026
CVE-2021-26828
CVE-2021-26828
Description
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- OpenPLC/ScadaBRdescription
- Range: <=0.9.1 (Linux), <=1.12.4 (Windows)
Patches
Vulnerability mechanics
References
5- github.com/SCADA-LTS/Scada-LTS/pull/2174nvdIssue TrackingPatch
- forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3615/4nvdBroken LinkExploitVendor Advisory
- packetstormsecurity.com/files/162564/ScadaBR-1.0-1.1CE-Linux-Shell-Upload.htmlnvdExploitThird Party Advisory
- youtu.be/k1teIStQr1AnvdExploitThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.