CODESYS
CODESYS Control V3 Untrusted Boot Application Advisory
Pages
5
Time to read
6 mins
Publication
Language
English
Pages
5
Time to read
6 mins
Publication
Language
English
This document is a security advisory detailing a vulnerability in the CODESYS Control runtime system, identified as CVE-2025-41660. It outlines the implications of this vulnerability, which allows low-privileged remote attackers to replace the boot application of the CODESYS Control runtime system, potentially enabling unauthorized code execution on the PLC. The advisory specifies affected products and versions, including CODESYS Control RTE and various other CODESYS Control products. It provides remediation steps, recommending updates to specific versions to mitigate the vulnerability. Additionally, it discusses alternative mitigation strategies, such as enforcing the use of signed applications and adjusting user group permissions. General security recommendations are also presented to enhance the overall security posture of CODESYS runtime systems. The advisory concludes with acknowledgments and disclaimers regarding the information provided.