CVE-2025-41658

Severity
5.5MEDIUM
EPSS
0.0%
top 95.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 4

Description

CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages12 packages

CVEListV5codesys/runtime_toolkit0.0.0.03.5.21.20
CVEListV5codesys/virtual_control_sl0.0.0.04.16.0.0
CVEListV5codesys/control_for_linux_sl0.0.0.04.16.0.0
CVEListV5codesys/control_for_pfc100_sl0.0.0.04.16.0.0
CVEListV5codesys/control_for_pfc200_sl0.0.0.04.16.0.0

🔴Vulnerability Details

2
CVEList
CODESYS Toolkit Exposes Sensitive Files via Default Permissions2025-08-04
GHSA
GHSA-ff63-c723-v97g: CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions2025-08-04
CVE-2025-41658 (MEDIUM CVSS 5.5) | CODESYS Runtime Toolkit-based produ | cvebase.io