<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:38:52 +0000</lastBuildDate>
    <item>
      <title>Advisory2025-09_VDE-2025-099 — CODESYS Control - Linux/QNX SysSocket flaw</title>
      <link>https://cve.radiocsirt.org/vuln/advisory2025-09_vde-2025-099</link>
      <description>&lt;p&gt;A vulnerability has been identified in the CODESYS Control runtime system, which includes an abstraction layer designed to ensure compatibility across different operating systems. This layer is used both by affected CODESYS products and by applications running on the PLC.&lt;/p&gt;
&lt;p&gt;The platform-specific adaptation of this abstraction layer for Linux and QNX contains a flaw in the SysSocket implementation. Due to incorrect internal handling and depending on how the caller interacts with the affected function, the issue can lead to an out-of-bounds read.&lt;/p&gt;
&lt;p&gt;An unauthenticated attacker may be able to exploit this vulnerability via socket-based communication, potentially causing a crash of the corresponding communication task. Additionally, also clients such as the PLCHandler running on Linux or QNX may be affected if they connect to a malicious server that triggers the flaw.&lt;/p&gt;
&lt;p&gt;Successful exploitation requires the attacker to win a race condition, which increases the complexity of the attack.&lt;/p&gt;
&lt;p&gt;Note: All platforms other than Linux and QNX are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in the CODESYS Control runtime system, which includes an abstraction layer designed to ensure compatibility across different operating systems. This layer is used both by affected CODESYS products and by applications running on the PLC.&lt;/p&gt;
&lt;p&gt;The platform-specific adaptation of this abstraction layer for Linux and QNX contains a flaw in the SysSocket implementation. Due to incorrect internal handling and depending on how the caller interacts with the affected function, the issue can lead to an out-of-bounds read.&lt;/p&gt;
&lt;p&gt;An unauthenticated attacker may be able to exploit this vulnerability via socket-based communication, potentially causing a crash of the corresponding communication task. Additionally, also clients such as the PLCHandler running on Linux or QNX may be affected if they connect to a malicious server that triggers the flaw.&lt;/p&gt;
&lt;p&gt;Successful exploitation requires the attacker to win a race condition, which increases the complexity of the attack.&lt;/p&gt;
&lt;p&gt;Note: All platforms other than Linux and QNX are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/advisory2025-09_vde-2025-099</guid>
    </item>
    <item>
      <title>bdu:2025-16472</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-16472</link>
      <description>bdu:2025-16472</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-16472</guid>
    </item>
    <item>
      <title>EUVD-2026-265086</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265086</link>
      <description>EUVD-2026-265086</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265086</guid>
    </item>
    <item>
      <title>fkie_cve-2025-41739</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-41739</link>
      <description>&lt;p&gt;An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-41739</guid>
    </item>
    <item>
      <title>GHSA-5qp2-82v4-wwr8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5qp2-82v4-wwr8</link>
      <description>&lt;p&gt;An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5qp2-82v4-wwr8</guid>
    </item>
    <item>
      <title>VDE-2025-081 — WAGO: Multiple PLCs and Communication Components are Affected by multiple Vulnerabilities leading to RCE</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-081</link>
      <description>&lt;p&gt;Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are &amp;lt;4.10.0 (FW32) and &amp;lt;4.10.0 (70).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are &amp;lt;4.10.0 (FW32) and &amp;lt;4.10.0 (70).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-081</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2700 — CODESYS Control und Development System: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2700</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in CODESYS Control und Development System ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen oder einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in CODESYS Control und Development System ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen oder einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2700</guid>
    </item>
  </channel>
</rss>
