Summary

Nozomi Networks Labs has disclosed a chain of three vulnerabilities in the widely-used CODESYS Control runtime that, when exploited together, allow attackers to gain root-level control over industrial devices. The vulnerabilities affect PLCs and Soft PLCs across critical sectors including manufacturing, energy, and water systems.

The attack chain works in stages: CVE-2025-41658 (CVSS 5.5) exposes password hashes through incorrect default permissions. CVE-2025-41659 (CVSS 8.3) reveals cryptographic materials that let attackers bypass code signing. CVE-2025-41660 (CVSS 8.8) allows uploading tampered project files that execute with root privileges on reboot. An attacker starting with basic Service-level credentials can chain all three to achieve full Administrator control.

The implications are severe: root access on industrial controllers means the ability to manipulate physical processes, alter sensor data, bypass safety mechanisms, and potentially cause physical damage. CODESYS has released patches in Control Runtime version 4.21.0.0 and Runtime Toolkit version 3.5.22.0, along with mandatory code signing for PLC applications.

Sources

Commentary

CODESYS is one of the most widely deployed PLC programming environments in the world — used across hundreds of manufacturers and thousands of industrial installations. A vulnerability chain that gets you from “basic credentials” to “root on the controller” is about as bad as ICS security gets.

What makes this particularly dangerous is the reboot trigger. The malicious code sits dormant until the system restarts, which makes detection harder and means the compromise could survive standard runtime monitoring. For operators in critical infrastructure: patch immediately, segment your OT networks, and audit who has Service-level access. The days of assuming your PLC network is “air-gapped enough” are long over.

By Allan