U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-41738

Change History

Initial Analysis by NIST 2/23/2026 10:42:30 AM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
          *cpe:2.3:a:codesys:control_for_beaglebone_sl:*:*:*:*:*:*:*:* versions from (including) 4.5.0.0 up to (excluding) 4.19.0.0
          *cpe:2.3:a:codesys:control_rte_sl:*:*:*:*:*:*:*:* versions from (including) 3.5.18.0 up to (excluding) 3.5.21.40
          *cpe:2.3:a:codesys:control_rte_sl_(for_beckhoff_cx):*:*:*:*:*:*:*:* versions from (including) 3.5.18.0 up to (excluding) 3.5.21.40
          *cpe:2.3:a:codesys:control_win_sl:*:*:*:*:*:*:*:* versions from (including) 3.5.18.0 up to (excluding) 3.5.21.40
          *cpe:2.3:a:codesys:control_for_empc-a/imx6_sl:*:*:*:*:*:*:*:* versions from (including) 4.5.0.0 up to (including) 4.19.0.0
          *cpe:2.3:a:codesys:control_for_iot2000_sl:*:*:*:*:*:*:*:* versions from (including) 4.5.0.0 up to (excluding) 4.19.0.0
          *cpe:2.3:a:codesys:control_for_linux_arm_sl:*:*:*:*:*:*:*:* versions from (including) 4.5.0.0 up to (excluding) 4.19.0.0
          *cpe:2.3:a:codesys:control_for_linux_sl:*:*:*:*:*:*:*:* versions from (including) 4.5.0.0 up to (excluding) 4.19.0.0
          *cpe:2.3:a:codesys:control_for_pfc100_sl:*:*:*:*:*:*:*:* versions from (including) 4.5.0.0 up to (including) 4.19.0.0
          *cpe:2.3:a:codesys:control_for_pfc200_sl:*:*:*:*:*:*:*:* versions from (including) 4.5.0.0 up to (excluding) 4.19.0.0
          *cpe:2.3:a:codesys:control_for_plcnext_sl:*:*:*:*:*:*:*:* versions from (including) 4.5.0.0 up to (excluding) 4.19.0.0
          *cpe:2.3:a:codesys:control_for_raspberry_pi_sl:*:*:*:*:*:*:*:* versions from (including) 4.5.0.0 up to (excluding) 4.19.0.0
          *cpe:2.3:a:codesys:control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:* versions from (including) 4.5.0.0 up to (including) 4.19.0.0
          *cpe:2.3:a:codesys:hmi_sl:*:*:*:*:*:*:*:* versions from (including) 3.5.18.0 up to (excluding) 3.5.21.40
          *cpe:2.3:a:codesys:remote_target_visu:*:*:*:*:*:*:*:* versions from (including) 3.5.18.0 up to (excluding) 3.5.21.40
          *cpe:2.3:a:codesys:runtime_toolkit:*:*:*:*:*:*:*:* versions from (including) 3.5.18.0 up to (excluding) 3.5.21.40
          *cpe:2.3:a:codesys:virtual_control_sl:*:*:*:*:*:*:*:* versions from (including) 4.5.0.0 up to (excluding) 4.19.0.0
Added Reference Type

								
							
							
						
CERT VDE: https://certvde.com/de/advisories/VDE-2025-100 Types: Third Party Advisory