Attackers Can Backdoor CODESYS Applications by Chaining Vulnerabilities
ID: fe6d4d79-472a-5cda-a6fe-7cb43b0c167f
STIX ID: report--fe6d4d79-472a-5cda-a6fe-7cb43b0c167f
Feed Name: cybersecurityNews.com
Multiple high-impact vulnerabilities in the widely used CODESYS Control runtime (CVE-2025-41658/41659/41660) let local or authenticated attackers extract password hashes and cryptographic material and restore tampered boot applications; chained together an attacker can upload a backdoored PLC application, obtain root/administrator control, and manipulate industrial processes. CODESYS released fixes (Control Runtime 4.21.0.0, Toolkit 3.5.22.0), enabled mandatory code signing by default, and the advisory recommends applying updates, enforcing network segmentation, and monitoring industrial traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
