PT-2025-31799 · Codesys · Codesys Control

Luca Borzacchiello

·

Published

2025-08-04

·

Updated

2026-04-27

·

CVE-2025-41659

CVSS v2.0

8.7

High

AV:N/AC:L/Au:S/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions CODESYS Control (affected versions not specified)
Description A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system. This allows the attacker to read and write certificates and their keys, potentially enabling the extraction of sensitive data or the acceptance of certificates as trusted. If the certificates are deleted, only unencrypted communication is possible, while all services remain available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2026-00081
CVE-2025-41659

Affected Products

Codesys Control