CVE-2025-41691
EUVD-2025-2349004.08.2025, 08:15
An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| codesys | control_rte_sl | 3.5.21.10 ≤ 𝑥 < 3.5.21.20 | CNA |
| codesys | control_rte_sl | 4.16.0.0 ≤ 𝑥 < 4.17.0.0 | CNA |
Common Weakness Enumeration