CVE-2021-34605 | Xinje XD/E Series PLC Program Tool Zip Slip
Exp
A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by initiating an upload program request from an infected Xinje PLC. This can result in remote code execution, information disclosure and denial of service of the system running the XINJE XD/E Series PLC Program Tool.
Conclusion & alert: CVE-2021-34605 is rated High Exploit Risk (74.4/100): CVSS High severity, with medium exploitation likelihood (EPSS 2.33%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.76% over the last day, indicating growing attacker interest.Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2021-34605
Exploit prediction scoring system (EPSS) score for CVE-2021-34605
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).