cbcvebase.
CVE-2025-41658
published 2025-08-04

CVE-2025-41658: CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.

Affected

12 ranges
VendorProductVersion rangeFixed in
codesyscontrol_for_beaglebone_sl>= 0.0.0.0 < 4.16.0.04.16.0.0
codesyscontrol_for_empc-a_imx6_sl>= 0.0.0.0 < 4.16.0.04.16.0.0
codesyscontrol_for_iot2000_sl>= 0.0.0.0 < 4.16.0.04.16.0.0
codesyscontrol_for_linux_arm_sl>= 0.0.0.0 < 4.16.0.04.16.0.0
codesyscontrol_for_linux_sl>= 0.0.0.0 < 4.16.0.04.16.0.0
codesyscontrol_for_pfc100_sl>= 0.0.0.0 < 4.16.0.04.16.0.0
codesyscontrol_for_pfc200_sl>= 0.0.0.0 < 4.16.0.04.16.0.0
codesyscontrol_for_plcnext_sl>= 0.0.0.0 < 4.16.0.04.16.0.0
codesyscontrol_for_raspberry_pi_sl>= 0.0.0.0 < 4.16.0.04.16.0.0
codesyscontrol_for_wago_touch_panels_600_sl>= 0.0.0.0 < 4.16.0.04.16.0.0
codesysruntime_toolkit>= 0.0.0.0 < 3.5.21.203.5.21.20
codesysvirtual_control_sl>= 0.0.0.0 < 4.16.0.04.16.0.0