Soft PLC Backdoors Survive Restarts in CODESYS Runtime
CODESYS Control runtimes can be turned into persistent root-level backdoors, not just crashed or briefly tampered with. The weak point is backup and restore logic in the Raspberry Pi SL variant, which lets an authenticated low-privilege user pull cryptographic material, bypass code signing and encryption, and replace the control application with malicious logic that comes back after restart.
Nozomi Networks Labs says the issue affects CODESYS Control for Raspberry Pi SL and a broader set of CODESYS Control runtimes. The three flaws are tracked as CVE-2025-41658, CVE-2025-41659, and CVE-2025-41660, and CODESYS has issued patches; the affected footprint includes manufacturing, energy, water, and other industrial control environments.
The practical risk is persistence inside soft PLCs. Once malicious logic is restored with root privileges, transient detection and simple reboot-based recovery no longer clear the compromise.