CVE-2023-3526: Phoenixcontact Cloud Client 1101t-Tx Firmware
Critical severity, CVSS 9.6. EPSS: 1.8% chance of exploitation in the next 30 days.
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.
Affected products
- Phoenixcontact Cloud Client 1101t-Tx Firmware: before 2.06.10 (fixed in 2.06.10)
- Phoenixcontact Tc Cloud Client 1002-4g Att Firmware: before 2.07.2 (fixed in 2.07.2)
- Phoenixcontact Tc Cloud Client 1002-4g Firmware: before 2.07.2 (fixed in 2.07.2)
- Phoenixcontact Tc Cloud Client 1002-4g Vzw Firmware: before 2.07.2 (fixed in 2.07.2)
- Phoenixcontact Tc Router 3002t-4g Att Firmware: before 2.07.2 (fixed in 2.07.2)
- Phoenixcontact Tc Router 3002t-4g Firmware: before 2.07.2 (fixed in 2.07.2)
- Phoenixcontact Tc Router 3002t-4g Vzw Firmware: before 2.07.2 (fixed in 2.07.2)
Published 2023-08-08. Last modified 2026-06-17.