CVE-2025-41656

CRITICAL LAB

Node_RED - RCE

Title source: llm

Description

An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default.

Exploits (1)

nomisec WORKING POC 2 stars
by wallyschag · poc
https://github.com/wallyschag/CVE-2025-41656

Scores

CVSS v3 10.0
EPSS 0.0025
EPSS Percentile 48.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull nodered/node-red:3.1.0-18

Details

CWE
CWE-306
Status published
Products (1)
Pilz/IndustrialPI 4 with Firmware Bullseye < 2024-08
Published Jul 01, 2025
Tracked Since Feb 18, 2026