CVE-2026-22321: Phoenix Contact Fl Nat 2008

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A stack-based buffer overflow in the device's Telnet/SSH CLI login routine occurs when a unauthenticated attacker send an oversized or unexpected username input. An overflow condition crashes the thread handling the login attempt, forcing the session to close. Because other CLI sessions remain unaffected, the impact is limited to a low‑severity availability disruption.

Affected products

Published 2026-03-18. Last modified 2026-06-17.