CVE-2025-41659Disclosure

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-26); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-26: 1Mentions · 2026-05-01: 1Technical Details · 2026-05-01: 104-2605-01
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • blackorbird@blackorbird
    Disclosure

    Backdooring CODESYS Applications via Vulnerability Chaining #PLC CVE-2025-41658 + CVE-2025-41659 + CVE-2025-41660 https://www.nozominetworks.com/blog/backdooring-codesys-applications-via-vulnerability-chaining https://t.co/4OJyigA3VG

    Post summary

    A blog post announces three new CVEs (CVE-2025-41658, CVE-2025-41659, CVE-2025-41660) that enable backdooring CODESYS applications through vulnerability chaining.

    19136155.2K
    42.7K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    Nozomi researchers chain CVE-2025-41658, CVE-2025-41659, and CVE-2025-41660 in CODESYS Control runtime, allowing authenticated attackers to inject malicious code and achieve root-level control of PLCs across manufacturing, energy, and water sec... #DFIR_Radar https://t.co/45GfiHZygt

    Post summary

    Nozomi researchers disclosed a chain of CVEs in CODESYS Control runtime that enable authenticated attackers to inject code and gain root-level control of PLCs across manufacturing, energy, and water sectors.

    100101.0K
    1.7K followersView on X

Explore more