CVE-2025-41656 is a remote code execution vulnerability affecting Node-RED deployments that are left in the default unauthenticated configuration. According to the provided content, the issue exists when the Node-RED administrative/editor interface is exposed and the adminAuth setting in settings.js is undefined, allowing unauthenticated access to the editor. An attacker can connect to the exposed Node-RED service, typically on TCP port 1880 or 41880, create or deploy malicious flows, and use Node-RED exec nodes to invoke arbitrary operating system commands. The content states that all Node-RED releases up to and including 3.1.8 are affected when deployed without authentication, and highlights particular exposure in industrial automation, IoT, and KUNBUS Revolution Pi PLC environments with firmware up to 01/2025.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept exploit for CVE-2025-41656, an unauthenticated remote code execution vulnerability in NodeRED. The main exploit script (cve_2025_41656.py) targets a NodeRED instance by sending a malicious flow via the NodeRED REST API, which includes an 'exec' node configured to execute a bash reverse shell. The attacker must set up a listener (e.g., with netcat) and adjust the script to point to their own IP and the target NodeRED instance. The repository includes supporting files for a SCADA lab environment, such as a Dockerfile for OpenPLC with WiringPi, a docker-compose file to orchestrate NodeRED and OpenPLC containers, and a Structured Text (ST) program for the PLC. The exploit demonstrates how an attacker can gain shell access to the NodeRED container in a typical industrial control system setup if proper authentication and network segmentation are not enforced. No evidence of fake or destructive code was found; the exploit is a functional PoC for research and demonstration purposes.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.