← Back

CVE-2025-41738

nvd nist
Published: Dec 1, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: info@cert.vde.com (Secondary)

Description

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.

Affected (17)

17 products
Control For Beaglebone Sl
Control For Empc A/imx6 Sl
Control For Iot2000 Sl
Control For Linux Arm Sl
Control For Linux Sl
Control For Pfc100 Sl
Control For Pfc200 Sl
Control For Plcnext Sl
Control For Raspberry Pi Sl
Control Rte Sl
Control Rte Sl (for Beckhoff Cx)
Control Win Sl
Hmi Sl
Remote Target Visu
Runtime Toolkit
Virtual Control Sl
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
From 4.5.0.0 to 4.19.0.0
From 4.5.0.0 to 4.19.0.0
From 4.5.0.0 to 4.19.0.0
From 4.5.0.0 to 4.19.0.0
From 4.5.0.0 to 4.19.0.0
From 4.5.0.0 to 4.19.0.0
From 4.5.0.0 to 4.19.0.0
From 4.5.0.0 to 4.19.0.0
From 4.5.0.0 to 4.19.0.0
From 4.5.0.0 to 4.19.0.0
From 3.5.18.0 to 3.5.21.40
From 3.5.18.0 to 3.5.21.40
From 3.5.18.0 to 3.5.21.40
From 3.5.18.0 to 3.5.21.40
From 3.5.18.0 to 3.5.21.40
From 3.5.18.0 to 3.5.21.40
From 4.5.0.0 to 4.19.0.0

References (1)

Source: info@cert.vde.com
Third Party Advisory

Timeline

No history available yet.