CVE-2025-41665: Phoenix Contact Axc F 1152
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect default permissions of a config file.
Affected products
- Phoenix Contact Axc F 1152: before 2025.0.2 (fixed in 2025.0.2)
- Phoenix Contact Axc F 2152: before 2025.0.2 (fixed in 2025.0.2)
- Phoenix Contact Axc F 3152: before 2025.0.2 (fixed in 2025.0.2)
- Phoenix Contact Bpc 9102s: before 2025.0.2 (fixed in 2025.0.2)
- Phoenix Contact Rfc 4072s: before 2025.0.2 (fixed in 2025.0.2)
Published 2025-07-08. Last modified 2026-06-17.