PT-2025-48433 · Codesys · Codesys Control Runtime

Published

2025-12-01

·

Updated

2026-02-23

·

CVE-2025-41738

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions CODESYS Control Runtime (affected versions not specified)
Description An unauthenticated remote attacker can cause the visualization server of the CODESYS Control runtime system to access a resource with an incorrect pointer type, potentially leading to a denial-of-service (DoS) condition. This issue does not require authentication for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16471
CVE-2025-41738

Affected Products

Codesys Control Runtime