cbcvebase.
CVE-2025-0694
published 2025-03-18

CVE-2025-0694: Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.

PriorityP429medium6.6CVSS 3.1
AVPACLPRLUINSUCHIHAH
EPSS
0.26%
17.2th percentile
Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.

Affected

15 ranges
VendorProductVersion rangeFixed in
codesyscodesys_control_for_beaglebone_sl< 4.16.0.04.16.0.0
codesyscodesys_control_for_empc-a_imx6_sl< 4.16.0.04.16.0.0
codesyscodesys_control_for_iot2000_sl< 4.16.0.04.16.0.0
codesyscodesys_control_for_linux_arm_sl< 4.16.0.04.16.0.0
codesyscodesys_control_for_linux_sl< 4.16.0.04.16.0.0
codesyscodesys_control_for_pfc100_sl< 4.16.0.04.16.0.0
codesyscodesys_control_for_pfc200_sl< 4.16.0.04.16.0.0
codesyscodesys_control_for_plcnext_sl< 4.16.0.04.16.0.0
codesyscodesys_control_for_raspberry_pi_sl< 4.16.0.04.16.0.0
codesyscodesys_control_for_wago_touch_panels_600_sl< 4.16.0.04.16.0.0
codesyscodesys_control_rte< 3.5.21.03.5.21.0
codesyscodesys_control_rte_sl< 3.5.21.03.5.21.0
codesyscodesys_control_win< 3.5.21.03.5.21.0
codesyscodesys_runtime_toolkit< 3.5.21.03.5.21.0
codesyscodesys_virtual_control_sl< 4.16.0.04.16.0.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.