Skip to main content
HIGH

CVE-2021-34605

CVSS v3

7.3

HIGH

EPSS Score

2.5 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by initiating an upload program request from an infected Xinje PLC. This can result in remote code execution, information disclosure and denial of service of the system running the XINJE XD/E Series PLC Program Tool.

Technical details

Published
2022-05-11

Frequently asked questions

What is CVE-2021-34605?

A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by initiating an upload program request from an infected Xinje PLC. This can result in remote code execution, information disclosure and denial of service of the system running the XINJE XD/E Series PLC Program Tool.

Is CVE-2021-34605 actively exploited?

Active exploitation of CVE-2021-34605 has not been confirmed. Its EPSS score was 2.5% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-34605?

CVE-2021-34605 has a CVSS v3 base score of 7.3 (HIGH severity).

Is CVE-2021-34605 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key