CVE-2025-41658: CODESYS Toolkit Exposes Sensitive Files via Default Permissions
CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41658?
CVE-2025-41658 is regarded as a medium severity vulnerability due to the potential exposure of sensitive files to low-privileged users.
How do I fix CVE-2025-41658?
To fix CVE-2025-41658, adjust the file permissions on CODESYS Runtime Toolkit-based products to prevent unauthorized access.
Who is affected by CVE-2025-41658?
CVE-2025-41658 affects users of CODESYS Runtime Toolkit-based products that have default file permissions in place.
What are the consequences of CVE-2025-41658?
The consequences of CVE-2025-41658 include unauthorized access to sensitive files by local low-privileged operating system users.
Is CVE-2025-41658 easy to exploit?
CVE-2025-41658 can be easily exploited by a low-privileged user with access to the operating system where the CODESYS Runtime Toolkit is installed.