CVE-2026-79625: high-severity vulnerability in CODESYS Control for BeagleBone SL
Improper Synchronization in Monitoring in CODESYS Control Runtime
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
CODESYS · Control for BeagleBone SLCODESYS · Control for emPC-A/iMX6 SLCODESYS · Control for IOT2000 SLCODESYS · Control for Linux ARM SLCODESYS · Control for Linux SLCODESYS · Control for PFC100 SLCODESYS · Control for PFC200 SLCODESYS · Control for PLCnext SLCODESYS · Control for Raspberry Pi SLCODESYS · Control for WAGO Touch Panels 600 SLCODESYS · Control RTE (for Beckhoff CX) SLCODESYS · Control RTE (SL)CODESYS · Control Win (SL)CODESYS · Development System 3CODESYS · HMI (SL)CODESYS · Runtime ToolkitCODESYS · Safety SIL2CODESYS · Virtual Control SLRelated CVEs — CODESYS Control for BeagleBone SL
In the same product, most dangerous first.
CVE-2022-4224HIGHCODESYS: Exposure of Resource to Wrong Sphere in CODESYS V3EPSS 0.9%CVE-2025-41691HIGHCODESYS Control DoS via Unauthenticated NULL Pointer DereferenceEPSS 0.5%CVE-2025-41659HIGHCODESYS Control PKI Exposure Enables Remote Certificate AccessEPSS 0.2%CVE-2025-41658MEDIUMCODESYS Toolkit Exposes Sensitive Files via Default PermissionsEPSS 0.1%