How to Unlock PLC Passwords with Free Tools

If you have ever encountered a situation where you need to access or modify a PLC program but you don't have the password, you know how frustrating it can be. PLC passwords are designed to protect the intellectual property and safety of the program, but sometimes they can also prevent authorized users from making necessary changes or troubleshooting problems.

Fortunately, there are some free tools available online that can help you crack PLC passwords for various brands and models. In this article, we will introduce some of these tools and show you how to use them effectively.

What is PLC Password Cracking?

PLC password cracking is the process of recovering passwords from data that has been stored or transmitted by a computer system. The purpose of PLC password cracking might be to help a user recover a forgotten password, install a new password that is less of a security risk, or gain unauthorized access to a system.

There are different methods and techniques for PLC password cracking, depending on the type and level of encryption used by the PLC. Some of the most common methods are:

  • Brute force attack: This method involves trying every possible combination of characters until the correct password is found. This can be very time-consuming and ineffective for long or complex passwords.

  • Dictionary attack: This method involves using a list of common or likely passwords and trying them one by one. This can be faster than brute force, but it still depends on the quality and size of the dictionary.

  • Reverse engineering: This method involves analyzing the PLC program or firmware to find clues or vulnerabilities that can reveal the password. This can be very difficult and requires advanced skills and tools.

  • Social engineering: This method involves tricking or persuading someone who knows the password to reveal it or give access to the system. This can be very effective but also risky and unethical.

What are Some Free PLC Password Cracking Tools?

There are many free PLC password cracking tools available online, but not all of them are reliable or compatible with every PLC brand and model. Some of the most popular and trusted tools are:

  • PLC Unlock BD: This tool can crack passwords for various PLC brands, such as Omron, Mitsubishi, Delta, Siemens, Fatek, Fuji-Hakko, Idec, AB, Vigor, Panasonic, Pro-face, Weintek, and Hi-tech. It can also crack passwords for some HMI models. You can download it from

  • PLC Backup Tools: This tool can crack passwords for Omron PLCs with Tool bus & SYSMAC WAY connection, such as C200H, CP1H, CP1L, CP1E, CJ2M, CG1G, CJ1M. You can download it from

  • S7 Password Cracker: This tool can crack passwords for Siemens S7 PLCs using a SCADA vulnerability. You can download it from

How to Use PLC Password Cracking Tools?

The exact steps for using PLC password cracking tools may vary depending on the tool and the PLC model, but in general they follow these steps:

  • Connect your PC to the PLC using the appropriate cable and communication protocol.

  • Run the PLC password cracking tool and select the PLC brand and model.

  • Follow the instructions on the tool's interface to scan or upload the PLC program or data.

  • Wait for the tool to analyze the data and find the password.

  • Copy or enter the password to access or modify the PLC program.


PLC password cracking can be a useful skill for troubleshooting or modifying PLC programs when you don't have the original password.


