CVE-2025-41726: Beckhoff: Arbitrary code execution within privileged processes
A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the Device Manager or locally via an API and can cause integer overflows which then may lead to arbitrary code execution within privileged processes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41726?
CVE-2025-41726 has a high severity rating due to its potential to allow arbitrary code execution by low privileged remote attackers.
How do I fix CVE-2025-41726?
To fix CVE-2025-41726, update to the latest version of the Beckhoff Device Manager that addresses this vulnerability.
Who is affected by CVE-2025-41726?
CVE-2025-41726 affects users of the Beckhoff Device Manager software, particularly those using vulnerable versions.
What types of attacks can CVE-2025-41726 facilitate?
CVE-2025-41726 can facilitate arbitrary code execution and integer overflow attacks if exploited.
Is CVE-2025-41726 exploitable over the network?
Yes, CVE-2025-41726 is exploitable remotely through specially crafted calls sent to the web service of the Device Manager.