CVE-2025-41669: Phoenix Contact Axc F 1152
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.
Affected products
- Phoenix Contact Axc F 1152: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
- Phoenix Contact Axc F 1252: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
- Phoenix Contact Axc F 2000 Ea: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
- Phoenix Contact Axc F 2152: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
- Phoenix Contact Axc F 3152: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
- Phoenix Contact Bpc 9102s: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
- Phoenix Contact Epc 1522: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
- Phoenix Contact Rfc 4072r: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
- Phoenix Contact Rfc 4072s: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
- Phoenix Contact VL3 Upc 2440 Edge: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
- Phoenix Contact Vplcnext Control 1000: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
- Phoenix Contact Vplcnext Control 2000: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
- Phoenix Contact Vplcnext Control 3000: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
- Phoenix Contact Vplcnext Control 500: from 0.0.0, before 2026.0.3 (fixed in 2026.0.3)
Published 2026-05-27. Last modified 2026-06-17.