CVE-2025-41700 - CVE House
Back to Database
Status published High CVE-2025-41700

CODESYS Development System - Deserialization of Untrusted Data

Vulnerability Description

An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41700

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • MengyuXia from Beijing Aerospace Wanyuan Science & Technology Co, Ltd.

Affected Vendor

Affected Software

CODESYS Development System
Vulnerable Versions:
0.0.0

Timeline

Official Publish: December 1st, 2025
Last Modified: December 1st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)