CVE-2025-41739: Codesys Control For Beaglebone Sl

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.

Affected products

  • Codesys Codesys Control For Beaglebone Sl: from 4.15.0.0, before 4.19.0.0 (fixed in 4.19.0.0)
  • Codesys Codesys Control For Empc-a/imx6 Sl: from 4.15.0.0, before 4.19.0.0 (fixed in 4.19.0.0)
  • Codesys Codesys Control For IOT2000 Sl: from 4.15.0.0, before 4.19.0.0 (fixed in 4.19.0.0)
  • Codesys Codesys Control For Linux Arm Sl: from 4.15.0.0, before 4.19.0.0 (fixed in 4.19.0.0)
  • Codesys Codesys Control For Linux Sl: from 4.15.0.0, before 4.19.0.0 (fixed in 4.19.0.0)
  • Codesys Codesys Control For PFC100 Sl: from 4.15.0.0, before 4.19.0.0 (fixed in 4.19.0.0)
  • Codesys Codesys Control For PFC200 Sl: from 4.15.0.0, before 4.19.0.0 (fixed in 4.19.0.0)
  • Codesys Codesys Control For Plcnext Sl: from 4.15.0.0, before 4.19.0.0 (fixed in 4.19.0.0)
  • Codesys Codesys Control For Raspberry Pi Sl: from 4.15.0.0, before 4.19.0.0 (fixed in 4.19.0.0)
  • Codesys Codesys Control For Wago Touch Panels 600 Sl: from 4.15.0.0, before 4.19.0.0 (fixed in 4.19.0.0)
  • Codesys Codesys Edge Gateway For Linux: from 4.15.0.0, before 4.19.0.0 (fixed in 4.19.0.0)
  • Codesys Codesys Plchandler: from 3.5.21.0, before 3.5.21.40 (fixed in 3.5.21.40)
  • Codesys Codesys Remote Target Visu: from 3.5.21.0, before 3.5.21.40 (fixed in 3.5.21.40)
  • Codesys Codesys Runtime Toolkit: from 3.5.21.0, before 3.5.21.40 (fixed in 3.5.21.40)
  • Codesys Codesys Targetvisu For Linux Sl: from 4.15.0.0, before 4.19.0.0 (fixed in 4.19.0.0)
  • Codesys Codesys Virtual Control Sl: from 4.15.0.0, before 4.19.0.0 (fixed in 4.19.0.0)

Published 2025-12-01. Last modified 2026-06-17.