Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PHOENIX CONTACT — Vulnerabilities & Security Advisories 169

Browse all 169 CVE security advisories affecting PHOENIX CONTACT. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PHOENIX CONTACT specializes in industrial automation, electrical engineering, and electronics, providing critical infrastructure components such as programmable logic controllers, power supplies, and industrial networking devices. With 142 recorded CVEs, the company’s software ecosystem has historically been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These flaws often stem from inadequate input validation in web-based management interfaces or insecure default configurations in embedded systems. Notable incidents include exploitable authentication bypasses and buffer overflow errors that could allow attackers to gain unauthorized control over industrial control systems. The high volume of vulnerabilities suggests persistent challenges in securing legacy firmware and web applications. While the hardware itself is robust, the associated software layers require rigorous patching and secure coding practices to mitigate risks in operational technology environments.

CVE ID Title CVSS Severity Published
CVE-2026-22320 Stack-Based Buffer Overflow in TFTP File-Transfer Command Handling over CLI — FL SWITCH 2005 CWE-121 6.5 Medium 2026-03-18
CVE-2026-22319 Stack-Based Buffer Overflow in File Install Parameter Handling — FL SWITCH 2005 CWE-121 4.9 Medium 2026-03-18
CVE-2026-22318 Stack-Based Buffer Overflow in File Transfer Parameter Handling — FL SWITCH 2005 CWE-121 4.9 Medium 2026-03-18
CVE-2026-22317 Command Injection Vulnerability in Root CA Certificate Transfer Workflow — FL SWITCH 2005 CWE-77 7.2 High 2026-03-18
CVE-2026-22316 Buffer Overflow using TFTP Filename — FL SWITCH 2005 CWE-121 6.5 Medium 2026-03-18
CVE-2025-41717 Config-Upload Code Injection — TC ROUTER 3002T-3G CWE-94 8.8 High 2026-01-13
CVE-2025-41693 Authenticated Denial-of-Service via SSH — FL SWITCH 2005 CWE-770 4.3 Medium 2025-12-09
CVE-2025-41696 Hardcoded User Password — FL SWITCH 2005 CWE-798 4.6 Medium 2025-12-09
CVE-2025-41694 Authenticated Denial-of-Service via Webshell — FL SWITCH 2005 CWE-770 6.5 Medium 2025-12-09
CVE-2025-41692 Weak/Predictable root Password — FL SWITCH 2005 CWE-916 6.8 Medium 2025-12-09
CVE-2025-41697 Shell access to UART Console — FL SWITCH 2005 CWE-1299 6.8 Medium 2025-12-09
CVE-2025-41695 Reflected XSS vulnerability in dyn_conn.php — FL SWITCH 2005 CWE-79 7.1 High 2025-12-09
CVE-2025-41745 Reflected XSS vulnerability in pxc_portCntr2.php — FL SWITCH 2005 CWE-79 7.1 High 2025-12-09
CVE-2025-41746 Reflected XSS vulnerability in pxc_portSecCfg.php — FL SWITCH 2005 CWE-79 7.1 High 2025-12-09
CVE-2025-41747 Reflected XSS vulnerability in pxc_vlanIntfCfg.php — FL SWITCH 2005 CWE-79 7.1 High 2025-12-09
CVE-2025-41748 Reflected XSS vulnerability in pxc_Dot1xCfg.php — FL SWITCH 2005 CWE-79 7.1 High 2025-12-09
CVE-2025-41749 Reflected XSS vulnerability in port_util.php — FL SWITCH 2005 CWE-79 7.1 High 2025-12-09
CVE-2025-41750 Reflected XSS vulnerability in pxc_PortCfg.php — FL SWITCH 2005 CWE-79 7.1 High 2025-12-09
CVE-2025-41751 Reflected XSS vulnerability in pxc_portCntr.php — FL SWITCH 2005 CWE-79 7.1 High 2025-12-09
CVE-2025-41752 Reflected XSS vulnerability in pxc_portSfp.php — FL SWITCH 2005 CWE-79 7.1 High 2025-12-09
CVE-2025-41699 Phoenix Contact: Security Advisory for CHARX SEC-3xxx charging controllers — CHARX SEC-3150 CWE-94 8.8 High 2025-10-14
CVE-2025-41707 Phoenix Contact: WebSocket Handler Denial of Service — QUINT4-UPS/24DC/24DC/5/EIP CWE-120 5.3 Medium 2025-10-14
CVE-2025-41706 Phoenix Contact: Webserver Denial of Service through Malformed Content-Length — QUINT4-UPS/24DC/24DC/5/EIP CWE-120 5.3 Medium 2025-10-14
CVE-2025-41705 Phoenix Contact: WebSocket Message Interception Leaks Webfrontend Credentials — QUINT4-UPS/24DC/24DC/5/EIP CWE-523 6.8 Medium 2025-10-14
CVE-2025-41704 Phoenix Contact: Unauthenticated Modbus Service DoS via Crafted Function Code — QUINT4-UPS/24DC/24DC/5/EIP CWE-770 5.3 Medium 2025-10-14
CVE-2025-41703 Phoenix Contact: UPS Shutdown via Unauthenticated Modbus Command — QUINT4-UPS/24DC/24DC/5/EIP CWE-306 7.5 High 2025-10-14
CVE-2025-41686 Improper File Permissions Allow Local Privilege Escalation — DaUM CWE-306 7.8 High 2025-08-12
CVE-2025-2813 HTTP Service DoS Vulnerability — AXL F BK PN TPS CWE-770 7.5 High 2025-07-31
CVE-2025-41668 Phoenix Contact: File access due to the replacement of a critical file used by the service security-profile — AXC F 1152 CWE-59 8.8 High 2025-07-08
CVE-2025-41667 Phoenix Contact: File access due to the replacement of a critical file used by the arp-preinit script — AXC F 1152 CWE-59 8.8 High 2025-07-08

This page lists every published CVE security advisory associated with PHOENIX CONTACT. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.