CVE-2025-0694: Codesys Control For Beaglebone Sl

Medium severity, CVSS 6.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.

Affected products

  • Codesys Codesys Control For Beaglebone Sl: before 4.16.0.0 (fixed in 4.16.0.0)
  • Codesys Codesys Control For Empc-a/imx6 Sl: before 4.16.0.0 (fixed in 4.16.0.0)
  • Codesys Codesys Control For IOT2000 Sl: before 4.16.0.0 (fixed in 4.16.0.0)
  • Codesys Codesys Control For Linux Arm Sl: before 4.16.0.0 (fixed in 4.16.0.0)
  • Codesys Codesys Control For Linux Sl: before 4.16.0.0 (fixed in 4.16.0.0)
  • Codesys Codesys Control For PFC100 Sl: before 4.16.0.0 (fixed in 4.16.0.0)
  • Codesys Codesys Control For PFC200 Sl: before 4.16.0.0 (fixed in 4.16.0.0)
  • Codesys Codesys Control For Plcnext Sl: before 4.16.0.0 (fixed in 4.16.0.0)
  • Codesys Codesys Control For Raspberry Pi Sl: before 4.16.0.0 (fixed in 4.16.0.0)
  • Codesys Codesys Control For Wago Touch Panels 600 Sl: before 4.16.0.0 (fixed in 4.16.0.0)
  • Codesys Codesys Control Rte For Beckhoff Cx Sl: before 3.5.21.0 (fixed in 3.5.21.0)
  • Codesys Codesys Control Rte Sl: before 3.5.21.0 (fixed in 3.5.21.0)
  • Codesys Codesys Control Win Sl: before 3.5.21.0 (fixed in 3.5.21.0)
  • Codesys Codesys Runtime Toolkit: before 3.5.21.0 (fixed in 3.5.21.0)
  • Codesys Codesys Virtual Control Sl: before 4.16.0.0 (fixed in 4.16.0.0)

Published 2025-03-18. Last modified 2026-06-17.