CVE-2025-2595 Details
Description
An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.
A vulnerability exists in CODESYS Visualization versions prior to 4.8.0.0, allowing unauthenticated remote attackers to bypass user management and access visualization template files or static elements through forced browsing. This issue is present in various CODESYS Control products, all prior to version 4.15.0.0, as well as in CODESYS Control RTE (for Beckhoff CX) SL, CODESYS Control RTE (SL), CODESYS Control Win (SL), CODESYS HMI (SL), CODESYS Runtime Toolkit, CODESYS Embedded Target Visu Toolkit, and CODESYS Remote Target Visu Toolkit, all versions prior to 3.5.21.0.
Users should update CODESYS Visualization to version 4.8.0.0. For CODESYS Control products, an update to version 4.15.0.0 is required. Additionally, CODESYS Control RTE (SL), CODESYS Control RTE (for Beckhoff CX) SL, CODESYS Control Win (SL), CODESYS HMI (SL), CODESYS Runtime Toolkit, CODESYS Embedded Target Visu Toolkit, and CODESYS Remote Target Visu Toolkit should be updated to version 3.5.21.0. After updating, existing CODESYS projects that include a CODESYS WebVisu must be recompiled and downloaded to the updated HMI or PLC.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 23, 2025CISA-ADP
Assessed Apr 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://certvde.com/en/advisories/VDE-2025-027 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-425 | Direct Request ('Forced Browsing') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CODESYS Control | All versions |
CPE
Remediation
| |
| CODESYS Control RTE | All versions |
CPE
Remediation
| |
| CODESYS Control Win | All versions |
CPE
Remediation
| |
| CODESYS Embedded Target Visu Toolkit | All versions |
CPE
Remediation
| |
| CODESYS HMI | All versions |
CPE
Remediation
| |
| CODESYS Remote Target Visu Toolkit | All versions |
CPE
Remediation
| |
| CODESYS Runtime Toolkit | All versions |
CPE
Remediation
| |
| CODESYS Virtual Control | All versions |
CPE
Remediation
| |
| CODESYS Visualization | < 4.8.0.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2025 | New CVE Received | [email protected] |
Volerion