Home

Description

A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.

PUBLISHED Reserved 2025-04-16 | Published 2026-03-24 | Updated 2026-03-24 | Assigner CERTVDE




HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-669 Incorrect Resource Transfer Between Spheres

Product status

Default status
unaffected

0.0.0 (semver) before 3.5.22.0
affected

Default status
unaffected

0.0.0 (semver) before 3.5.22.0
affected

Default status
unaffected

0.0.0 (semver) before 3.5.22.0
affected

Default status
unaffected

0.0.0 (semver) before 3.5.22.0
affected

Default status
unaffected

0.0.0 (semver) before 3.5.22.0
affected

Default status
unaffected

0.0.0 (semver) before 4.21.0.0
affected

Default status
unaffected

0.0.0 (semver) before 4.21.0.0
affected

Default status
unaffected

0.0.0 (semver) before 4.21.0.0
affected

Default status
unaffected

0.0.0 (semver) before 4.21.0.0
affected

Default status
unaffected

0.0.0 (semver) before 4.21.0.0
affected

Default status
unaffected

0.0.0 (semver) before 4.21.0.0
affected

Default status
unaffected

0.0.0 (semver) before 4.21.0.0
affected

Default status
unaffected

0.0.0 (semver) before 4.21.0.0
affected

Default status
unaffected

0.0.0 (semver) before 4.21.0.0
affected

Default status
unaffected

0.0.0 (semver) before 4.21.0.0
affected

Default status
unaffected

0.0.0 (semver) before 4.21.0.0
affected

Credits

Luca Borzacchiello from Nozomi Networks finder

References

certvde.com/de/advisories/VDE-2026-011

cve.org (CVE-2025-41660)

nvd.nist.gov (CVE-2025-41660)

Download JSON