CVE-2025-41738

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
References
Link Resource
https://certvde.com/de/advisories/VDE-2025-100 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_arm_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_win_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:remote_target_visu:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:runtime_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:virtual_control_sl:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-01 10:16

Updated : 2026-02-23 15:42


NVD link : CVE-2025-41738

Mitre link : CVE-2025-41738

CVE.ORG link : CVE-2025-41738


JSON object : View

Products Affected

codesys

  • control_for_beaglebone_sl
  • control_win_sl
  • control_for_iot2000_sl
  • control_for_raspberry_pi_sl
  • control_for_empc-a\/imx6_sl
  • control_for_plcnext_sl
  • remote_target_visu
  • control_rte_sl_\(for_beckhoff_cx\)
  • runtime_toolkit
  • virtual_control_sl
  • control_for_pfc100_sl
  • hmi_sl
  • control_for_linux_arm_sl
  • control_rte_sl
  • control_for_pfc200_sl
  • control_for_linux_sl
  • control_for_wago_touch_panels_600_sl
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')