CVE-2025-41700
EUVD-2025-19997401.12.2025, 10:16
An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| codesys | codesys | 𝑥 < 3.5.21.40 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| codesys | development_system | 0.0.0 ≤ 𝑥 < 3.5.21.40 | CNA |
Common Weakness Enumeration