CVE-2025-41700: Codesys
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.
Affected products
- Codesys Codesys: before 3.5.21.40 (fixed in 3.5.21.40)
Published 2025-12-01. Last modified 2026-06-17.