CVE-2025-41656: Pilz: Missing Authentication in Node-RED integration
Published Jul 1, 2025
·Updated
An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the NodeRED server is not configured by default.
Affected Software
1 affected component
Node-RED Node-RED
Event History
Jul 1, 2025
CVE Published
via MITRE·08:10 AM
Data Sourced
via MITRE·08:10 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-41656?
CVE-2025-41656 is considered high severity due to the potential for unauthenticated remote command execution.
2
How do I fix CVE-2025-41656?
To fix CVE-2025-41656, ensure that authentication for the Node-RED server is properly configured and enabled.
3
What vulnerabilities does CVE-2025-41656 exploit?
CVE-2025-41656 exploits the lack of default authentication in Node-RED that allows remote command execution.
4
Who is affected by CVE-2025-41656?
All installations of Node-RED without authentication configuration are affected by CVE-2025-41656.
5
What should I do if my system is impacted by CVE-2025-41656?
If your system is impacted by CVE-2025-41656, immediately secure your Node-RED installation by implementing authentication.