CVE-2025-41669
The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.
Published:May 27, 2026
Last Modified:May 27, 2026
EPS:May 27, 2026
EPSS Score:0.00058
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Phoenix Contact
Product
Axc F 1152
Phoenix Contact
Axc F 1152
Vendor
Phoenix Contact
Product
Axc F 1252
Phoenix Contact
Axc F 1252
Vendor
Phoenix Contact
Product
Axc F 2000 Ea
Phoenix Contact
Axc F 2000 Ea
Vendor
Phoenix Contact
Product
Axc F 2152
Phoenix Contact
Axc F 2152
Vendor
Phoenix Contact
Product
Axc F 3152
Phoenix Contact
Axc F 3152
Vendor
Phoenix Contact
Product
Bpc 9102s
Phoenix Contact
Bpc 9102s
Vendor
Phoenix Contact
Product
Epc 1522
Phoenix Contact
Epc 1522
Vendor
Phoenix Contact
Product
Rfc 4072r
Phoenix Contact
Rfc 4072r
Vendor
Phoenix Contact
Product
Rfc 4072s
Phoenix Contact
Rfc 4072s
Vendor
Phoenix Contact
Product
Vl3 Upc 2440 Edge
Phoenix Contact
Vl3 Upc 2440 Edge
Vendor
Phoenix Contact
Product
Vplcnext Control 1000
Phoenix Contact
Vplcnext Control 1000
Vendor
Phoenix Contact
Product
Vplcnext Control 2000
Phoenix Contact
Vplcnext Control 2000
Vendor
Phoenix Contact
Product
Vplcnext Control 3000
Phoenix Contact
Vplcnext Control 3000
Vendor
Phoenix Contact
Product
Vplcnext Control 500
Phoenix Contact
Vplcnext Control 500
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
