CVE-2025-41738: CODESYS Control - Invalid type usage in visualization
Published Dec 1, 2025
·Updated
An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
Affected Software
18 affected components
CODESYS CODESYS Control
CODESYS Control For Beaglebone Sl>=4.5.0.0<4.19.0.0
CODESYS Control For Empc-a\/imx6 Sl>=4.5.0.0<=4.19.0.0
CODESYS Control For Iot2000 Sl>=4.5.0.0<4.19.0.0
CODESYS Control For Linux Arm Sl>=4.5.0.0<4.19.0.0
CODESYS Control For Linux Sl>=4.5.0.0<4.19.0.0
CODESYS Control For Pfc100 Sl>=4.5.0.0<=4.19.0.0
CODESYS Control For Pfc200 Sl>=4.5.0.0<4.19.0.0
CODESYS Control For Plcnext Sl>=4.5.0.0<4.19.0.0
CODESYS Control For Raspberry Pi Sl>=4.5.0.0<4.19.0.0
CODESYS Control For Wago Touch Panels 600 Sl>=4.5.0.0<=4.19.0.0
CODESYS Control Rte Sl>=3.5.18.0<3.5.21.40
CODESYS Control Rte Sl \(for Beckhoff Cx\)>=3.5.18.0<3.5.21.40
CODESYS Control Win Sl>=3.5.18.0<3.5.21.40
CODESYS Hmi Sl>=3.5.18.0<3.5.21.40
CODESYS Remote Target Visu>=3.5.18.0<3.5.21.40
CODESYS Runtime Toolkit>=3.5.18.0<3.5.21.40
CODESYS Virtual Control Sl>=4.5.0.0<4.19.0.0
Event History
Dec 1, 2025
CVE Published
via MITRE·10:02 AM
Data Sourced
via MITRE·10:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41738?
CVE-2025-41738 is classified as a high severity vulnerability due to its potential to cause a denial-of-service condition.
2
How do I fix CVE-2025-41738?
To mitigate CVE-2025-41738, ensure you update to the latest version of the CODESYS Control software as provided by the vendor.
3
Who is affected by CVE-2025-41738?
CVE-2025-41738 affects users of the CODESYS Control runtime system.
4
What type of attack does CVE-2025-41738 enable?
CVE-2025-41738 allows an unauthenticated remote attacker to potentially trigger a denial-of-service condition.
5
Is authentication required to exploit CVE-2025-41738?
No, CVE-2025-41738 can be exploited by an unauthenticated remote attacker.