CVE-2025-34226 - CVE House
Back to Database
Status published High CVE-2025-34226

OpenPLC Runtime v3 Persistent DoS

Vulnerability Description

OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be crafted to induce corruption of the programs database. After a successful malformed upload the runtime continues to operate until a restart; on restart the runtime can fail to start because of corrupted database entries, resulting in persistent denial of service requiring complete rebase of the product to recover. This vulnerability was remediated by commit 095ee09.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34226

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Eyodav (Mike G.A)

Affected Vendor

Autonomy Logic

View all reports →

Affected Software

OpenPLC Runtime
Vulnerable Versions:
3.0

Timeline

Official Publish: October 3rd, 2025
Last Modified: June 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)