← All Advisories

CVE-2025-41670

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2025-41670

Key Details

CVECVE-2025-41670
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-427 (Uncontrolled Search Path Element)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Phoenix ContactAXC F 1152
Phoenix ContactAXC F 1252
Phoenix ContactAXC F 2000 EA
Phoenix ContactAXC F 2152
Phoenix ContactAXC F 3152
Phoenix ContactBPC 9102S
Phoenix ContactEPC 1522
Phoenix ContactRFC 4072R
Phoenix ContactRFC 4072S
Phoenix ContactVL3 UPC 2440 EDGE
Phoenix ContactVPLCNEXT CONTROL 1000
Phoenix ContactVPLCNEXT CONTROL 2000
Phoenix ContactVPLCNEXT CONTROL 3000
Phoenix ContactVPLCNEXT CONTROL 500
SubsystemsGeneral OT
SectorsMultiple

What to Know

A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the filesystem. The affected service processes data from locations that are not sufficiently protected against modification by low-privileged users. As the service runs with elevated privileges, successful exploitation may result in a local privilege escalation. (NVD)

What to Do

Monitor Phoenix Contact's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-41670
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-41670