CVE-2025-41648: Pilz: Authentication Bypass in IndustrialPI Webstatus
Published Jul 1, 2025
·Updated
An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all available settings of the IndustrialPI.
Affected Software
1 affected component
Pilz IndustrialPI
Event History
Jul 1, 2025
CVE Published
via MITRE·08:10 AM
Data Sourced
via MITRE·08:10 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-41648?
CVE-2025-41648 is classified as a high-severity vulnerability due to its potential for remote exploitation.
2
Who is affected by CVE-2025-41648?
CVE-2025-41648 affects the Pilz IndustrialPI web application.
3
How do I fix CVE-2025-41648?
To mitigate CVE-2025-41648, it is recommended to apply the latest security updates released by Pilz for IndustrialPI.
4
What can attackers do by exploiting CVE-2025-41648?
Exploitation of CVE-2025-41648 allows unauthenticated remote attackers to bypass login and alter all settings of IndustrialPI devices.
5
Is CVE-2025-41648 being actively exploited?
As of now, there have been reports of active exploitation of CVE-2025-41648 in the wild.