CVE-2023-1109: Phoenixcontact Energy Axc Pu

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.

Affected products

  • Phoenixcontact Energy Axc Pu: from 01.00.00.00, up to and including 04.15.00.00
  • Phoenixcontact Infobox Firmware: from 01.00.00.00, up to and including 02.02.00.00
  • Phoenixcontact Smartrtu Axc Ig Firmware: from 01.00.00.00, up to and including 01.02.00.01
  • Phoenixcontact Smartrtu Axc SG Firmware: from 01.00.00.00, up to and including 01.08.00.02

Published 2023-04-17. Last modified 2026-06-17.