Back to Database
Status published
Critical
CVE-2025-41648
Pilz: Authentication Bypass in IndustrialPI Webstatus
Vulnerability Description
An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all available settings of the IndustrialPI.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41648
Credits & Attribution
No credits recorded in the NVD database.
More from Pilz
View All →CVE-2025-41656
Pilz: Missing Authentication in Node-RED integration
Critical
10
CVE-2023-45796
XSS vulnerability in Pilz PASvisu and PMI v8xx
High
8.1
CVE-2023-45795
Pilz: XSS vulnerability in Pilz PASvisu and PMI v8xx
High
7.8
CVE-2018-19009
Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated...
High
7.8
Affected Vendor
Pilz
View all reports →Affected Software
IndustrialPI 4 with IndustrialPI webstatus
Vulnerable Versions:
0
Timeline
Official Publish:
July 1st, 2025
Last Modified:
July 2nd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.