← All Advisories

CVE-2025-41669

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2025-41669

Key Details

CVECVE-2025-41669
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-347 (Improper Verification of Cryptographic Signature)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Phoenix ContactAXC F 1152
Phoenix ContactAXC F 1252
Phoenix ContactAXC F 2000 EA
Phoenix ContactAXC F 2152
Phoenix ContactAXC F 3152
Phoenix ContactBPC 9102S
Phoenix ContactEPC 1522
Phoenix ContactRFC 4072R
Phoenix ContactRFC 4072S
Phoenix ContactVL3 UPC 2440 EDGE
Phoenix ContactVPLCNEXT CONTROL 1000
Phoenix ContactVPLCNEXT CONTROL 2000
Phoenix ContactVPLCNEXT CONTROL 3000
Phoenix ContactVPLCNEXT CONTROL 500
SubsystemsGeneral OT
SectorsMultiple

What to Know

The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control. (NVD)

What to Do

Monitor Phoenix Contact's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-41669
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-41669