CVE-2025-0694

CVSS 3.1 Score 6.6 of 10 (medium)

Details

Published Mar 18, 2025
CWE ID 22

Summary

CVE-2025-0694 is a new vulnerability affecting CODESYS Control software. attackers with limited privileges and physical access can exploit this insufficient path validation issue to gain unauthorized access to the full filesystem. This vulnerability poses a significant risk, as it enables attackers to potentially steal or modify sensitive data, install malware, or disrupt system operations. Successful exploitation requires direct access to the affected system, making it a targeted threat. CODESYS Control users are urged to update their software to the latest version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share