CVE-2025-41771: Phoenix Contact Axc F 1152

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.

Affected products

  • Phoenix Contact Axc F 1152: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Axc F 1252: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Axc F 2000 Ea: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Axc F 2152: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Axc F 3152: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Bpc 9102s: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Bpc 9202s: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Catan c1: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Epc 1502: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Epc 1522: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Rfc 4072r: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Rfc 4072s: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact VL3 Upc 2440 Edge: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Vplcnext Control 1000: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Vplcnext Control 2000: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Vplcnext Control 3000: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)
  • Phoenix Contact Vplcnext Control 500: from 2019.0.4, before 2026.0.3 (fixed in 2026.0.3)

Published 2026-08-12. Last modified 2026-09-29.