Back to Database
Status published
High
CVE-2025-41691
CODESYS Control DoS via Unauthenticated NULL Pointer Dereference
Vulnerability Description
An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41691
Credits & Attribution
No credits recorded in the NVD database.
More from CODESYS
View All →CVE-2025-41739
CODESYS Control - Linux/QNX SysSocket flaw
Medium
5.9
CVE-2025-41738
CODESYS Control - Invalid type usage in visualization
High
7.5
CVE-2025-41700
CODESYS Development System - Deserialization of Untrusted Data
High
7.8
CVE-2025-41660
CODESYS Control Boot Application Replacement Enables Code Execution
High
8.8
CVE-2025-41659
CODESYS Control PKI Exposure Enables Remote Certificate Access
High
8.3
Affected Vendor
CODESYS
View all reports →Affected Software
Control RTE (SL), Control RTE (for Beckhoff CX) SL, Control Win (SL), HMI (SL), Control for BeagleBone SL, Control for emPC-A/iMX6 SL, Control for IOT2000 SL, Control for Linux ARM SL, Control for Linux SL, Control for PFC100 SL, Control for PFC200 SL, Control for PLCnext SL, Control for Raspberry Pi SL, Control for WAGO Touch Panels 600 SL, Virtual Control SL
Vulnerable Versions:
3.5.21.10, 4.16.0.0
Timeline
Official Publish:
August 4th, 2025
Last Modified:
August 4th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H