CVE-2025-41660

Published Mar 24, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-41660 is a vulnerability affecting the CODESYS Control runtime system. It is described as a resource transfer flaw that enables a low-privileged remote attacker to replace the boot application of the system. This unauthorized replacement can lead to the execution of arbitrary code on the affected system. Exploitation of this vulnerability typically involves an attacker first obtaining service-level credentials. These credentials might be acquired through methods such as exploiting weak default passwords, compromising an engineer's workstation, or leveraging other vulnerabilities to steal local password hashes. Once authenticated, the attacker can then abuse the standard project backup workflow to upload and restore tampered project files.

Description
A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.
Source
info@cert.vde.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

info@cert.vde.com
CWE-669

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.