CVE-2025-41704: Phoenix Contact QUINT4-ups/24dc/24dc/10/eip
Medium severity, CVSS 5.3. EPSS: 1.6% chance of exploitation in the next 30 days.
An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-function code without affecting the core functionality.
Affected products
- Phoenix Contact QUINT4-ups/24dc/24dc/10/eip
- Phoenix Contact QUINT4-ups/24dc/24dc/20/eip
- Phoenix Contact QUINT4-ups/24dc/24dc/40/eip
- Phoenix Contact QUINT4-ups/24dc/24dc/5/eip
Published 2025-10-14. Last modified 2026-06-17.