CVE-2025-41707: Phoenix Contact QUINT4-ups/24dc/24dc/10/eip

Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.

The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a crafted websocket message to trigger the issue without affecting the core functionality.

Affected products

Published 2025-10-14. Last modified 2026-06-17.