CVE-2023-3526: Phoenixcontact Cloud Client 1101t-Tx Firmware

Critical severity, CVSS 9.6. EPSS: 1.8% chance of exploitation in the next 30 days.

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.

Affected products

  • Phoenixcontact Cloud Client 1101t-Tx Firmware: before 2.06.10 (fixed in 2.06.10)
  • Phoenixcontact Tc Cloud Client 1002-4g Att Firmware: before 2.07.2 (fixed in 2.07.2)
  • Phoenixcontact Tc Cloud Client 1002-4g Firmware: before 2.07.2 (fixed in 2.07.2)
  • Phoenixcontact Tc Cloud Client 1002-4g Vzw Firmware: before 2.07.2 (fixed in 2.07.2)
  • Phoenixcontact Tc Router 3002t-4g Att Firmware: before 2.07.2 (fixed in 2.07.2)
  • Phoenixcontact Tc Router 3002t-4g Firmware: before 2.07.2 (fixed in 2.07.2)
  • Phoenixcontact Tc Router 3002t-4g Vzw Firmware: before 2.07.2 (fixed in 2.07.2)

Published 2023-08-08. Last modified 2026-06-17.