An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
References
| Link | Resource |
|---|---|
| https://certvde.com/de/advisories/VDE-2025-100 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
23 Feb 2026, 15:42
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:hmi_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:runtime_toolkit:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:control_win_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:remote_target_visu:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:control_for_linux_arm_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:virtual_control_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:* cpe:2.3:a:codesys:control_rte_sl_\(for_beckhoff_cx\):*:*:*:*:*:*:*:* cpe:2.3:a:codesys:control_for_empc-a\/imx6_sl:*:*:*:*:*:*:*:* |
|
| First Time |
Codesys control For Plcnext Sl
Codesys control For Pfc100 Sl Codesys control For Linux Arm Sl Codesys remote Target Visu Codesys control Rte Sl \(for Beckhoff Cx\) Codesys control For Wago Touch Panels 600 Sl Codesys control For Raspberry Pi Sl Codesys control For Linux Sl Codesys hmi Sl Codesys virtual Control Sl Codesys control Rte Sl Codesys runtime Toolkit Codesys Codesys control For Iot2000 Sl Codesys control For Pfc200 Sl Codesys control For Empc-a\/imx6 Sl Codesys control For Beaglebone Sl Codesys control Win Sl |
|
| References | () https://certvde.com/de/advisories/VDE-2025-100 - Third Party Advisory |
01 Dec 2025, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-01 10:16
Updated : 2026-02-23 15:42
NVD link : CVE-2025-41738
Mitre link : CVE-2025-41738
CVE.ORG link : CVE-2025-41738
JSON object : View
Products Affected
codesys
- control_rte_sl
- control_for_linux_sl
- hmi_sl
- remote_target_visu
- virtual_control_sl
- control_for_empc-a\/imx6_sl
- runtime_toolkit
- control_win_sl
- control_for_pfc100_sl
- control_for_plcnext_sl
- control_for_pfc200_sl
- control_for_iot2000_sl
- control_rte_sl_\(for_beckhoff_cx\)
- control_for_wago_touch_panels_600_sl
- control_for_raspberry_pi_sl
- control_for_beaglebone_sl
- control_for_linux_arm_sl
CWE
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
