Project Subscriptions
| Vendors | Products |
|---|---|
|
Phoenix Contact
Subscribe
|
Axc F 1152
Subscribe
Axc F 1252
Subscribe
Axc F 2000 Ea
Subscribe
Axc F 2152
Subscribe
Axc F 3152
Subscribe
Bpc 9102s
Subscribe
Epc 1522
Subscribe
Rfc 4072r
Subscribe
Rfc 4072s
Subscribe
Vl3 Upc 2440 Edge
Subscribe
Vplcnext Control 1000
Subscribe
Vplcnext Control 2000
Subscribe
Vplcnext Control 3000
Subscribe
Vplcnext Control 500
Subscribe
|
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-050/ |
|
Wed, 27 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control. | |
| Title | Insufficient Verification of Data Authenticity | |
| First Time appeared |
Phoenix Contact
Phoenix Contact axc F 1152 Phoenix Contact axc F 1252 Phoenix Contact axc F 2000 Ea Phoenix Contact axc F 2152 Phoenix Contact axc F 3152 Phoenix Contact bpc 9102s Phoenix Contact epc 1522 Phoenix Contact rfc 4072r Phoenix Contact rfc 4072s Phoenix Contact vl3 Upc 2440 Edge Phoenix Contact vplcnext Control 1000 Phoenix Contact vplcnext Control 2000 Phoenix Contact vplcnext Control 3000 Phoenix Contact vplcnext Control 500 |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:a:phoenix_contact:axc_f_1152:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:axc_f_1252:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:axc_f_2000_ea:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:axc_f_2152:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:axc_f_3152:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:bpc_9102s:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:epc_1522:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:rfc_4072r:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:rfc_4072s:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:vl3_upc_2440_edge:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:vplcnext_control_1000:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:vplcnext_control_2000:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:vplcnext_control_3000:*:*:*:*:*:*:*:* cpe:2.3:a:phoenix_contact:vplcnext_control_500:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Phoenix Contact
Phoenix Contact axc F 1152 Phoenix Contact axc F 1252 Phoenix Contact axc F 2000 Ea Phoenix Contact axc F 2152 Phoenix Contact axc F 3152 Phoenix Contact bpc 9102s Phoenix Contact epc 1522 Phoenix Contact rfc 4072r Phoenix Contact rfc 4072s Phoenix Contact vl3 Upc 2440 Edge Phoenix Contact vplcnext Control 1000 Phoenix Contact vplcnext Control 2000 Phoenix Contact vplcnext Control 3000 Phoenix Contact vplcnext Control 500 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-05-27T12:04:07.823Z
Reserved: 2025-04-16T11:17:48.308Z
Link: CVE-2025-41669
Updated: 2026-05-27T12:04:03.164Z
Status : Deferred
Published: 2026-05-27T08:16:39.710
Modified: 2026-05-27T14:53:22.863
Link: CVE-2025-41669
No data.
OpenCVE Enrichment
Updated: 2026-05-27T11:00:12Z