CVE-2025-41656: Pilz Industrialpi 4 With Firmware Bullseye

Critical severity, CVSS 10.0. EPSS: 12.5% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default.

Affected products

  • Pilz Industrialpi 4 With Firmware Bullseye: up to and including 2024-08

Published 2025-07-01. Last modified 2026-06-17.