CVE-2025-41660
CVSS 8.8 HIGH: a low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system… EPSS 0.4% (34th percentile).
Vulnerabilities & Exploits · IoT / OT Attack
CODESYS Control runtimes can be turned into persistent root-level backdoors, not just crashed or briefly tampered with. The weak point is backup and restore logic in the Raspberry Pi SL variant, which lets an authenticated low-privilege user pull cryptographic material, bypass code signing and encryption, and replace the control application with malicious logic that comes back after restart.
Nozomi Networks Labs says the issue affects CODESYS Control for Raspberry Pi SL and a broader set of CODESYS Control runtimes. The three flaws are tracked as CVE-2025-41658, CVE-2025-41659, and CVE-2025-41660, and CODESYS has issued patches; the affected footprint includes manufacturing, energy, water, and other industrial control environments.
The practical risk is persistence inside soft PLCs. Once malicious logic is restored with root privileges, transient detection and simple reboot-based recovery no longer clear the compromise.
1 source · May 1
CVSS 8.8 HIGH: a low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system… EPSS 0.4% (34th percentile).
CVSS 8.3 HIGH: a low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. EPSS 0.2% (13th percentile).
CVSS 5.5 MEDIUM: cODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due… EPSS 0.1% (2nd percentile).
Industrial Cyber
Chained vulnerabilities in CODESYS runtime could allow root-level control of industrial devices, Nozomi warns - Industrial Cyber
Chained vulnerabilities in CODESYS runtime could allow root-level control of industrial devices, Nozomi researchers warn.
originalPart of the PlainSec briefing for 2026-05-01
Every edition of this story: Soft PLC Backdoors Survive Restarts in CODESYS Runtime