logo

Exploiting Vulnerabilities in XINJE PLC Program Tool

ID: c4d61302-4a7b-5820-be82-409700cebf38

STIX ID: report--c4d61302-4a7b-5820-be82-409700cebf38

Feed Name: Claroty Team82

Threat Score
72/100

Date Published: 2023-08-07

Date Updated: 2026-04-17

Author: Mashav Sapir

...
...

Team82 disclosed two vulnerabilities in XINJE's PLC Program Tool (CVE-2021-34605 and CVE-2021-34606) where specially crafted .xdp project files exploit a zip-slip arbitrary write and subsequent DLL hijacking to achieve code execution on engineering workstations, potentially allowing attackers to compromise PLCs and disrupt OT processes; disclosure was delayed due to limited vendor cooperation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.