Insecure default settings in CODESYS Runtime Toolkit 32 bit full and CODESYS PLCWinNT
No sign of exploitation. No public exploitation artifact known so far.
CODESYS V2 PLCWinNT and Runtime Toolkit 32 ship without password protection enabled by default, allowing anyone with access to the system to control industrial equipment without authentication. This is critical because it leaves industrial control systems completely unprotected from unauthorized access.
The vulnerability exists in CODESYS V2 versions prior to V2.4.7.57 where authentication is not enforced by default and no warning is presented to users when a controller lacks a configured password. An unauthenticated attacker with local or network access to the affected system can directly interact with the runtime without credentials, bypassing the intended access control mechanism.