CVE-2025-41738
HIGHCODESYS Control - DoS
Title source: llmDescription
An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
Scores
CVSS v3
7.5
EPSS
0.0012
EPSS Percentile
31.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-843
Status
published
Affected Products (17)
codesys/control_for_beaglebone_sl
< 4.19.0.0
codesys/control_for_empc-a\/imx6_sl
< 4.19.0.0
codesys/control_for_iot2000_sl
< 4.19.0.0
codesys/control_for_linux_arm_sl
< 4.19.0.0
codesys/control_for_linux_sl
< 4.19.0.0
codesys/control_for_pfc100_sl
< 4.19.0.0
codesys/control_for_pfc200_sl
< 4.19.0.0
codesys/control_for_plcnext_sl
< 4.19.0.0
codesys/control_for_raspberry_pi_sl
< 4.19.0.0
codesys/control_for_wago_touch_panels_600_sl
< 4.19.0.0
codesys/control_rte_sl
< 3.5.21.40
codesys/control_rte_sl_\(for_beckhoff_cx\)
< 3.5.21.40
codesys/control_win_sl
< 3.5.21.40
codesys/hmi_sl
< 3.5.21.40
codesys/remote_target_visu
< 3.5.21.40
... and 2 more
Timeline
Published
Dec 01, 2025
Tracked Since
Feb 18, 2026