Input Validation Flaw in OpenPLC Runtime by Autonomous Logic
CVE-2025-34226
What is CVE-2025-34226?
An input validation flaw in OpenPLC Runtime v3 allows attackers to craft malicious uploads through the /upload-program-action endpoint. The epoch_time field is not properly validated, leading to potential corruption of the program database. Once a malformed upload occurs, the runtime continues to function until the next restart, at which point it may fail to initialize due to corrupted database entries. This can cause persistent denial of service, necessitating a complete reinstallation to restore functionality. This critical issue has been addressed in a recent patch, emphasizing the importance of timely updates to ensure system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OpenPLC Runtime 3.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
