CVE-2025-41658General

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-276

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-26); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-26: 1Mentions · 2026-05-01: 1Technical Details · 2026-05-01: 104-2605-01
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-04-261
General1
2026-05-011
Disclosure1
Full discourse2 posts
  • blackorbird@blackorbird
    General

    Backdooring CODESYS Applications via Vulnerability Chaining #PLC CVE-2025-41658 + CVE-2025-41659 + CVE-2025-41660 https://www.nozominetworks.com/blog/backdooring-codesys-applications-via-vulnerability-chaining https://t.co/4OJyigA3VG

    Post summary

    The tweet announces a blog post about backdooring CODESYS applications via vulnerability chaining, but provides no explicit PoC, exploit details, patches, or technical specifics.

    19136155.2K
    42.7K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    Nozomi researchers chain CVE-2025-41658, CVE-2025-41659, and CVE-2025-41660 in CODESYS Control runtime, allowing authenticated attackers to inject malicious code and achieve root-level control of PLCs across manufacturing, energy, and water sec... #DFIR_Radar https://t.co/45GfiHZygt

    Post summary

    Nozomi researchers disclosed three chained vulnerabilities (CVE‑2025‑41658, CVE‑2025‑41659, CVE‑2025‑41660) in CODESYS Control runtime that allow authenticated attackers to inject malicious code and gain root-level control of PLCs across industrial sectors.

    100101.0K
    1.7K followersView on X

Explore more