CVE-2025-41771

Summary

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.

Affected Software

VendorProductVersion RangeStatus
Phoenix ContactAXC F 11522019.0.4 < 2026.0.3affected
Phoenix ContactAXC F 12522019.0.4 < 2026.0.3affected
Phoenix ContactAXC F 2000 EA2019.0.4 < 2026.0.3affected
Phoenix ContactAXC F 21522019.0.4 < 2026.0.3affected
Phoenix ContactAXC F 31522019.0.4 < 2026.0.3affected
Phoenix ContactBPC 9102S2019.0.4 < 2026.0.3affected
Phoenix ContactBPC 9202S2019.0.4 < 2026.0.3affected
Phoenix ContactRFC 4072R2019.0.4 < 2026.0.3affected
Phoenix ContactRFC 4072S2019.0.4 < 2026.0.3affected
Phoenix ContactVL3 UPC 2440 EDGE2019.0.4 < 2026.0.3affected
Phoenix ContactVPLCNEXT CONTROL 10002019.0.4 < 2026.0.3affected
Phoenix ContactVPLCNEXT CONTROL 20002019.0.4 < 2026.0.3affected
Phoenix ContactVPLCNEXT CONTROL 30002019.0.4 < 2026.0.3affected
Phoenix ContactVPLCNEXT CONTROL 5002019.0.4 < 2026.0.3affected
Phoenix ContactCatan C12019.0.4 < 2026.0.3affected
Phoenix ContactEPC 15022019.0.4 < 2026.0.3affected
Phoenix ContactEPC 15222019.0.4 < 2026.0.3affected

Weaknesses

  • CWE-89: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References