logo

Attackers Can Backdoor CODESYS Applications by Chaining Vulnerabilities

ID: fe6d4d79-472a-5cda-a6fe-7cb43b0c167f

STIX ID: report--fe6d4d79-472a-5cda-a6fe-7cb43b0c167f

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-27

Date Updated: 2026-05-08

Author: Abinaya

...
...

Multiple high-impact vulnerabilities in the widely used CODESYS Control runtime (CVE-2025-41658/41659/41660) let local or authenticated attackers extract password hashes and cryptographic material and restore tampered boot applications; chained together an attacker can upload a backdoored PLC application, obtain root/administrator control, and manipulate industrial processes. CODESYS released fixes (Control Runtime 4.21.0.0, Toolkit 3.5.22.0), enabled mandatory code signing by default, and the advisory recommends applying updates, enforcing network segmentation, and monitoring industrial traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.