CVE-2025-41660 details a critical vulnerability in the CODESYS Control runtime system, allowing a low-privileged remote attacker to replace the boot application and achieve unauthorized code execution. This high-severity flaw (CVSS 8.8) has low attack complexity and requires minimal privileges, posing a significant risk to confidentiality, integrity, and availability. While no public exploit code is currently available and it is not yet in CISA's Known Exploited Vulnerabilities catalog, the vulnerability is on an "Active" hot list and has generated notable community discussion, suggesting a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| CODESYS | CODESYS Control RTE (SL) | >= 0.0.0, < 3.5.22.0CNA affecteddefault unaffected | |
| CODESYS | CODESYS Control RTE (For Beckhoff CX) SL | >= 0.0.0, < 3.5.22.0CNA affecteddefault unaffected | |
| CODESYS | CODESYS Control Win (SL) | >= 0.0.0, < 3.5.22.0CNA affecteddefault unaffected | |
| CODESYS | CODESYS Control For BeagleBone SL | >= 0.0.0, < 4.21.0.0CNA affecteddefault unaffected | |
| CODESYS | CODESYS Control For IOT2000 SL | >= 0.0.0, < 4.21.0.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.