CVE-2025-41669 PUBLISHED

Insufficient Verification of Data Authenticity

Assigner: CERTVDE
Reserved: 16.04.2025 Published: 27.05.2026 Updated: 27.05.2026

The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Phoenix Contact
Product AXC F 1152
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product AXC F 1252
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product AXC F 2000 EA
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product AXC F 2152
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product AXC F 3152
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product BPC 9102S
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product EPC 1522
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product RFC 4072R
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product RFC 4072S
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product VL3 UPC 2440 EDGE
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product VPLCNEXT CONTROL 1000
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product VPLCNEXT CONTROL 2000
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product VPLCNEXT CONTROL 3000
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product VPLCNEXT CONTROL 500
Versions Default: unaffected
  • affected from 0.0.0 to 2026.0.3 (excl.)

Credits

  • Diego Giubertoni from Nozomi finder

References

Problem Types

  • CWE-347 Improper Verification of Cryptographic Signature CWE