The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.
History

Wed, 27 May 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.
Title Insufficient Verification of Data Authenticity
First Time appeared Phoenix Contact
Phoenix Contact axc F 1152
Phoenix Contact axc F 1252
Phoenix Contact axc F 2000 Ea
Phoenix Contact axc F 2152
Phoenix Contact axc F 3152
Phoenix Contact bpc 9102s
Phoenix Contact epc 1522
Phoenix Contact rfc 4072r
Phoenix Contact rfc 4072s
Phoenix Contact vl3 Upc 2440 Edge
Phoenix Contact vplcnext Control 1000
Phoenix Contact vplcnext Control 2000
Phoenix Contact vplcnext Control 3000
Phoenix Contact vplcnext Control 500
Weaknesses CWE-347
CPEs cpe:2.3:a:phoenix_contact:axc_f_1152:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:axc_f_1252:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:axc_f_2000_ea:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:axc_f_2152:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:axc_f_3152:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:bpc_9102s:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:epc_1522:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:rfc_4072r:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:rfc_4072s:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:vl3_upc_2440_edge:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:vplcnext_control_1000:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:vplcnext_control_2000:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:vplcnext_control_3000:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:vplcnext_control_500:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact axc F 1152
Phoenix Contact axc F 1252
Phoenix Contact axc F 2000 Ea
Phoenix Contact axc F 2152
Phoenix Contact axc F 3152
Phoenix Contact bpc 9102s
Phoenix Contact epc 1522
Phoenix Contact rfc 4072r
Phoenix Contact rfc 4072s
Phoenix Contact vl3 Upc 2440 Edge
Phoenix Contact vplcnext Control 1000
Phoenix Contact vplcnext Control 2000
Phoenix Contact vplcnext Control 3000
Phoenix Contact vplcnext Control 500
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published: 2026-05-27T07:18:28.236Z

Updated: 2026-05-27T07:18:28.236Z

Reserved: 2025-04-16T11:17:48.308Z

Link: CVE-2025-41669

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-27T08:16:39.710

Modified: 2026-05-27T08:16:39.710

Link: CVE-2025-41669

cve-icon Redhat

No data.