CVE-2025-41770 PUBLISHED

Unauthenticated Denial of Service

Assigner: CERTVDE
Reserved: 16.04.2025 Published: 12.08.2026 Updated: 12.08.2026

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Phoenix Contact
Product AXC F 1152
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product AXC F 1252
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product AXC F 2000 EA
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product AXC F 2152
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product AXC F 3152
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product BPC 9102S
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product BPC 9202S
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product RFC 4072R
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product RFC 4072S
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product VL3 UPC 2440 EDGE
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product VPLCNEXT CONTROL 1000
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product VPLCNEXT CONTROL 2000
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product VPLCNEXT CONTROL 3000
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product VPLCNEXT CONTROL 500
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product Catan C1
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product EPC 1502
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)
Vendor Phoenix Contact
Product EPC 1522
Versions Default: unaffected
  • affected from 2019.0.4 to 2026.0.3 (excl.)

Credits

  • CyberDanube finder

References

Problem Types

  • CWE-770 Allocation of Resources Without Limits or Throttling CWE