CVE-2026-22316: Phoenix Contact Fl Nat 2008

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request to trigger a stack-based Buffer Overflow, resulting in a DoS attack.

Affected products

Published 2026-03-18. Last modified 2026-06-17.