CVE-2025-41705: Phoenix Contact QUINT4-ups/24dc/24dc/10/eip
Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials for the Webfrontend.
Affected products
- Phoenix Contact QUINT4-ups/24dc/24dc/10/eip
- Phoenix Contact QUINT4-ups/24dc/24dc/20/eip
- Phoenix Contact QUINT4-ups/24dc/24dc/40/eip
- Phoenix Contact QUINT4-ups/24dc/24dc/5/eip
Published 2025-10-14. Last modified 2026-06-17.