CVE-2025-41717: Phoenix Contact Cloud Client 1101t-Tx/tx

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code injection as root. This results in a total loss of confidentiality, availability and integrity due to improper control of code generation ('Code Injection’).

Affected products

  • Phoenix Contact Cloud Client 1101t-Tx/tx: from 0.0.0, before 3.07.7 (fixed in 3.07.7)
  • Phoenix Contact Tc Cloud Client 1002-4g Att: from 0.0.0, before 3.08.8 (fixed in 3.08.8)
  • Phoenix Contact Tc Cloud Client 1002-Tx/tx: from 0.0.0, before 3.07.7 (fixed in 3.07.7)
  • Phoenix Contact Tc Router 2002t-3g: from 0.0.0, before 3.08.8 (fixed in 3.08.8)
  • Phoenix Contact Tc Router 2002t-4g: from 0.0.0, before 3.08.8 (fixed in 3.08.8)
  • Phoenix Contact Tc Router 3002t-3g: from 0.0.0, before 3.08.8 (fixed in 3.08.8)
  • Phoenix Contact Tc Router 3002t-4g: from 0.0.0, before 3.08.8 (fixed in 3.08.8)
  • Phoenix Contact Tc Router 3002t-4g Att: from 0.0.0, before 3.08.8 (fixed in 3.08.8)
  • Phoenix Contact Tc Router 3002t-4g Gl: from 0.0.0, before 3.08.8 (fixed in 3.08.8)
  • Phoenix Contact Tc Router 3002t-4g Vzw: from 0.0.0, before 3.08.8 (fixed in 3.08.8)
  • Phoenix Contact Tc Router 5004t-5g Eu: from 0.0.0, before 1.06.23 (fixed in 1.06.23)

Published 2026-01-13. Last modified 2026-06-17.