← Back to browse · API

CVE-2025-41656

Severity
CRITICAL
CVSS
10.0
EPSS
0.12424
Risk score
44.35
CISA KEV
No
PoC
No
Published
2025-07-01
Modified
2025-07-01
First seen
2026-08-07
Aliases
EUVD-2025-19648, GHSA-9J57-6X57-GPV5
Products
Pilz:IndustrialPI 4 with Firmware Bullseye 0 ≤2024-08
Sources
euvd EUVD-2025-19648

Description

An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default.

References