<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:48:48.221052+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2025-06_vde-2025-049</id>
    <title>Advisory2025-06_VDE-2025-049 — CODESYS Control V3 - Insecure default permissions</title>
    <updated>2026-10-03T18:48:48.316955+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>On certain operating systems (e.g., Linux), default file system permissions may allow read access to the files of the CODESYS Control runtime system for non-administrator users. The documentation provided with the CODESYS Runtime Toolkit does not explicitly address this risk. As a result, products based on the toolkit may unintentionally expose sensitive runtime files to local operating system users with limited privileges.</p>
<p>CODESYS Control runtime system based devices are affected if they provide access to the operating system (e.g., via a local user interface or SSH) and user accounts without administrator rights for this access exist or can be created.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2025-06_vde-2025-049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00083</id>
    <title>bdu:2026-00083</title>
    <updated>2026-10-03T18:48:48.317012+00:00</updated>
    <content>bdu:2026-00083</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00083"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-248925</id>
    <title>EUVD-2026-248925</title>
    <updated>2026-10-03T18:48:48.317030+00:00</updated>
    <content>EUVD-2026-248925</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-248925"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-41658</id>
    <title>fkie_cve-2025-41658</title>
    <updated>2026-10-03T18:48:48.317043+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-41658"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202601</id>
    <title>FSA-202601 — Several CODESYS vulnerabilities in Festo Automation Suite</title>
    <updated>2026-10-03T18:48:48.317066+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.</p>
<p>This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.</p>
<p>Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202601"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ff63-c723-v97g</id>
    <title>GHSA-ff63-c723-v97g</title>
    <updated>2026-10-03T18:48:48.317162+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ff63-c723-v97g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-076-01</id>
    <title>ICSA-26-076-01 — CODESYS in Festo Automation Suite</title>
    <updated>2026-10-03T18:48:48.317177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.</p>
<p>This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.</p>
<p>Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-076-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-005</id>
    <title>VDE-2026-005 — ifm: Multiple Vulnerabilities in CR3171</title>
    <updated>2026-10-03T18:48:48.317272+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Firmware installed on the CR3171 is impacted by various CODESYS vulnerabilities.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-005"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1705</id>
    <title>WID-SEC-W-2025-1705 — CODESYS: Mehrere Schwachstellen</title>
    <updated>2026-10-03T18:48:48.317289+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in CODESYS ausnutzen, um einen Denial-of-Service-Zustand auszulösen, Daten zu manipulieren und vertrauliche Informationen preiszugeben.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1705"/>
  </entry>
</feed>
