CVE-2025-41669
Last modified
CVE-2025-41669 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-41669?
How severe is CVE-2025-41669?
How do I fix CVE-2025-41669?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-41663For u-link Management API an unauthenticated remote attacker…9.8
- CVE-2025-41664A low-privileged remote attacker could gain unauthorized acc…7.5
- CVE-2025-41665An low privileged remote attacker can enforce the watchdog o…6.5
- CVE-2025-41666A low privileged remote attacker with file access can replac…8.8
- CVE-2025-41667A low privileged remote attacker with file access can replac…8.8
- CVE-2025-41668A low privileged remote attacker with file access can replac…8.8
- CVE-2025-41670A local user with low privileges may be able to influence th…8.7
- CVE-2025-41672A remote unauthenticated attacker may use default certificat…10
- CVE-2025-41673A high privileged remote attacker can execute arbitrary syst…7.2
- CVE-2025-41674A high privileged remote attacker can execute arbitrary syst…7.2
- CVE-2025-41675A high privileged remote attacker can execute arbitrary syst…7.2
- CVE-2025-41676A high privileged remote attacker can exhaust critical syste…4.9
Are you affected by CVE-2025-41669?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
