CVE-2025-41769

Summary

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

Affected Software

VendorProductVersion RangeStatus
Phoenix ContactAXC F 11522019.0.4 < 2026.0.3affected
Phoenix ContactAXC F 12522019.0.4 < 2026.0.3affected
Phoenix ContactAXC F 21522019.0.4 < 2026.0.3affected
Phoenix ContactAXC F 31522019.0.4 < 2026.0.3affected
Phoenix ContactBPC 9102S2019.0.4 < 2026.0.3affected
Phoenix ContactBPC 9202S2019.0.4 < 2026.0.3affected
Phoenix ContactRFC 4072R2019.0.4 < 2026.0.3affected
Phoenix ContactRFC 4072S2019.0.4 < 2026.0.3affected
Phoenix ContactVL3 UPC 2440 EDGE2019.0.4 < 2026.0.3affected
Phoenix ContactVPLCNEXT CONTROL 10002019.0.4 < 2026.0.3affected
Phoenix ContactVPLCNEXT CONTROL 20002019.0.4 < 2026.0.3affected
Phoenix ContactVPLCNEXT CONTROL 30002019.0.4 < 2026.0.3affected
Phoenix ContactVPLCNEXT CONTROL 5002019.0.4 < 2026.0.3affected
Phoenix ContactEPC 15022019.0.4 < 2026.0.3affected
Phoenix ContactEPC 15222019.0.4 < 2026.0.3affected

Weaknesses

  • CWE-120: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

References