cbcvebase.
CVE-2025-41691
published 2025-08-04

CVE-2025-41691: An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.

Affected

15 ranges
VendorProductVersion rangeFixed in
codesyscontrol_for_beaglebone_sl>= 4.16.0.0 < 4.17.0.04.17.0.0
codesyscontrol_for_empc-a_imx6_sl>= 4.16.0.0 < 4.17.0.04.17.0.0
codesyscontrol_for_iot2000_sl>= 4.16.0.0 < 4.17.0.04.17.0.0
codesyscontrol_for_linux_arm_sl>= 4.16.0.0 < 4.17.0.04.17.0.0
codesyscontrol_for_linux_sl>= 4.16.0.0 < 4.17.0.04.17.0.0
codesyscontrol_for_pfc100_sl>= 4.16.0.0 < 4.17.0.04.17.0.0
codesyscontrol_for_pfc200_sl>= 4.16.0.0 < 4.17.0.04.17.0.0
codesyscontrol_for_plcnext_sl>= 4.16.0.0 < 4.17.0.04.17.0.0
codesyscontrol_for_raspberry_pi_sl>= 4.16.0.0 < 4.17.0.04.17.0.0
codesyscontrol_for_wago_touch_panels_600_sl>= 4.16.0.0 < 4.17.0.04.17.0.0
codesyscontrol_rte>= 3.5.21.10 < 3.5.21.203.5.21.20
codesyscontrol_rte_sl>= 3.5.21.10 < 3.5.21.203.5.21.20
codesyscontrol_win>= 3.5.21.10 < 3.5.21.203.5.21.20
codesyshmi>= 3.5.21.10 < 3.5.21.203.5.21.20
codesysvirtual_control_sl>= 4.16.0.0 < 4.17.0.04.17.0.0