Vulnerabilities & Exploits · IoT / OT Attack

Soft PLC Backdoors Survive Restarts in CODESYS Runtime

CODESYS Control runtimes can be turned into persistent root-level backdoors, not just crashed or briefly tampered with. The weak point is backup and restore logic in the Raspberry Pi SL variant, which lets an authenticated low-privilege user pull cryptographic material, bypass code signing and encryption, and replace the control application with malicious logic that comes back after restart.

Nozomi Networks Labs says the issue affects CODESYS Control for Raspberry Pi SL and a broader set of CODESYS Control runtimes. The three flaws are tracked as CVE-2025-41658, CVE-2025-41659, and CVE-2025-41660, and CODESYS has issued patches; the affected footprint includes manufacturing, energy, water, and other industrial control environments.

The practical risk is persistence inside soft PLCs. Once malicious logic is restored with root privileges, transient detection and simple reboot-based recovery no longer clear the compromise.

1 source · May 1

CVE-2025-41660

NVD KEV

CVSS 8.8 HIGH: a low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system… EPSS 0.4% (34th percentile).

CVE-2025-41659

NVD KEV

CVSS 8.3 HIGH: a low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. EPSS 0.2% (13th percentile).

CVE-2025-41658

NVD KEV

CVSS 5.5 MEDIUM: cODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due… EPSS 0.1% (2nd percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-02

Every edition of this story: Soft PLC Backdoors Survive Restarts in CODESYS Runtime

More from today