CVE-2025-41660
Received
Received - Intake
Boot Application Replacement Vulnerability in CODESYS Control Runtime
Publication date: 2026-03-24
Last updated on: 2026-03-24
Assigner: CERT VDE
Description
Description
A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| codesys | control_rte | * |
| codesys | control | * |
| codesys | hmi | * |
| codesys | runtime_toolkit | * |
| codesys | virtual_control | to 3.5.22.0 (exc) |
| codesys | control | to 4.21.0.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-669 | The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource. |