CODESYS Runtime Vulnerabilities Enable Backdoor Attacks on Industrial Control Systems

CODESYS Runtime Vulnerabilities Enable Backdoor Attacks on Industrial Control Systems

First seen 1 May 2026, 15:37 UTC Industrialcyber.Cowww.nozominetworks.com 80% similarity 70.5

Article Content

Browse articles
ThreatCluster

Research from Nozomi Networks Labs has identified multiple vulnerabilities in the CODESYS Control runtime, allowing authenticated attackers to backdoor industrial control applications. The vulnerabilities, which include CVE-2025-41658, CVE-2025-41659, and CVE-2025-41660, enable attackers with Service-level credentials to replace legitimate applications with malicious ones that execute with root privileges. This poses a significant risk to CODESYS-powered PLCs used in critical sectors such as manufacturing, energy, and water systems. The flaws allow for the extraction of cryptographic material and bypassing of security protections like code signing. All identified vulnerabilities have been patched in the latest versions of CODESYS Control Runtime and Toolkit. Operators are urged to apply these updates immediately to mitigate risks. The attack vector primarily exploits weak credential management and can lead to severe operational disruptions.

Key Points: • Multiple vulnerabilities in CODESYS Control runtime allow backdoor attacks. • Attackers can exploit Service-level credentials to gain root access. • CODESYS has released patches for the identified vulnerabilities.

ThreatCluster AI

Timeline

2025-08-04
CVE-2025-41658 and CVE-2025-41659 published
2026-03-24
CVE-2025-41660 published
2026-05-01
Nozomi Networks Labs publishes vulnerability research

Community

Browse all →