CVE-2025-41700: CODESYS Development System - Deserialization of Untrusted Data
An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41700?
CVE-2025-41700 has been classified as a critical vulnerability due to its ability to allow unauthenticated attackers to execute arbitrary code.
How do I fix CVE-2025-41700?
To mitigate CVE-2025-41700, ensure that you only open CODESYS project files from trusted sources and apply any available patches from the vendor.
Who is affected by CVE-2025-41700?
CVE-2025-41700 affects users of the CODESYS Development System who handle project files.
What type of attack is associated with CVE-2025-41700?
CVE-2025-41700 is associated with a local code execution attack that exploits manipulated CODESYS project files.
Can I prevent exploitation of CVE-2025-41700?
Preventing exploitation of CVE-2025-41700 involves exercising caution when opening project files and implementing strong user training.