CVE-2025-41738

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
References
Link Resource
https://certvde.com/de/advisories/VDE-2025-100 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_arm_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_win_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:remote_target_visu:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:runtime_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:virtual_control_sl:*:*:*:*:*:*:*:*

History

23 Feb 2026, 15:42

Type Values Removed Values Added
CPE cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:hmi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:runtime_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_win_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:remote_target_visu:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_linux_arm_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:virtual_control_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:*
First Time Codesys control For Plcnext Sl
Codesys control For Pfc100 Sl
Codesys control For Linux Arm Sl
Codesys remote Target Visu
Codesys control Rte Sl \(for Beckhoff Cx\)
Codesys control For Wago Touch Panels 600 Sl
Codesys control For Raspberry Pi Sl
Codesys control For Linux Sl
Codesys hmi Sl
Codesys virtual Control Sl
Codesys control Rte Sl
Codesys runtime Toolkit
Codesys
Codesys control For Iot2000 Sl
Codesys control For Pfc200 Sl
Codesys control For Empc-a\/imx6 Sl
Codesys control For Beaglebone Sl
Codesys control Win Sl
References () https://certvde.com/de/advisories/VDE-2025-100 - () https://certvde.com/de/advisories/VDE-2025-100 - Third Party Advisory

01 Dec 2025, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-01 10:16

Updated : 2026-02-23 15:42


NVD link : CVE-2025-41738

Mitre link : CVE-2025-41738

CVE.ORG link : CVE-2025-41738


JSON object : View

Products Affected

codesys

  • control_rte_sl
  • control_for_linux_sl
  • hmi_sl
  • remote_target_visu
  • virtual_control_sl
  • control_for_empc-a\/imx6_sl
  • runtime_toolkit
  • control_win_sl
  • control_for_pfc100_sl
  • control_for_plcnext_sl
  • control_for_pfc200_sl
  • control_for_iot2000_sl
  • control_rte_sl_\(for_beckhoff_cx\)
  • control_for_wago_touch_panels_600_sl
  • control_for_raspberry_pi_sl
  • control_for_beaglebone_sl
  • control_for_linux_arm_sl
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')