CVE-2025-41648: Pilz Industrialpi 4 With Industrialpi Webstatus

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all available settings of the IndustrialPI.

Affected products

  • Pilz Industrialpi 4 With Industrialpi Webstatus: before 2.4.6 (fixed in 2.4.6)

Published 2025-07-01. Last modified 2026-06-17.