← All Advisories

CVE-2025-41769

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2025-41769

Key Details

CVECVE-2025-41769
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-09-29
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Phoenix ContactAXC F 1152
Phoenix ContactAXC F 1252
Phoenix ContactAXC F 2152
Phoenix ContactAXC F 3152
Phoenix ContactBPC 9102S
Phoenix ContactEPC 1522
Phoenix ContactRFC 4072R
Phoenix ContactRFC 4072S
Phoenix ContactVL3 UPC 2440 EDGE
Phoenix ContactVPLCNEXT CONTROL 1000
Phoenix ContactVPLCNEXT CONTROL 2000
Phoenix ContactVPLCNEXT CONTROL 3000
Phoenix ContactVPLCNEXT CONTROL 500
Phoenix ContactBPC 9202S
Phoenix ContactEPC 1502
SubsystemsGeneral OT
SectorsMultiple

What to Know

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code. (NVD)

What to Do

Monitor Phoenix Contact's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-41769
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-41769