CODESYS Development System - Deserialization of Untrusted Data
Vulnerability Description
An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41700
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- MengyuXia from Beijing Aerospace Wanyuan Science & Technology Co, Ltd.
More from CODESYS
View All →Affected Vendor
CODESYS
View all reports →