CVE-2025-46613

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 362

Summary

CVE-2025-46613 is a memory corruption vulnerability affecting OpenPLC versions 3 through 64f9c11. In server.cpp, a thread may access handleConnections arguments even after the parent stack frame has become unavailable, leading to unintended memory manipulation and potential code execution. This issue poses a serious security risk, as attackers could exploit it to gain unauthorized access to the system or execute malicious code. It is strongly recommended that users upgrade to a patched version of OpenPLC to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share