CVE-2025-41666
8.8Phoenix Contact · AXC F 1152, AXC F 2152, AXC F 3152, BPC 9102S, RFC 4072S
A low-privileged remote attacker can replace a critical watchdog file to gain arbitrary read, write, and execute access on affected Phoenix Contact industrial controllers.
Executive summary
This high-severity vulnerability in Phoenix Contact controllers allows authenticated attackers to achieve full system compromise by manipulating watchdog file operations.
Vulnerability
The flaw is caused by improper link resolution (CWE-59) during file access, allowing a low-privileged authenticated user to perform file replacement attacks against the system watchdog process.
Business impact
The ability to gain arbitrary read, write, and execute access on industrial control hardware presents a severe operational risk, potentially leading to unauthorized process manipulation, loss of control, or permanent hardware damage. With a CVSS score of 8.8, this vulnerability represents a high risk to the availability and integrity of industrial automation environments where these controllers are deployed.
Remediation
Immediate Action: Update all affected Phoenix Contact devices to firmware version 2025.0.2 or later as documented in the vendor advisory.
Proactive Monitoring: Monitor system logs for unauthorized file modification attempts or unexpected behavior in the watchdog service.
Compensating Controls: Restrict network access to the management interfaces of these controllers to trusted personnel and verify that low-privileged users are not granted unnecessary file system access permissions.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for total system compromise in critical industrial environments, immediate patching of the affected Phoenix Contact controllers is required. Organizations should prioritize firmware updates on all internet-exposed or remotely accessible devices to mitigate the risk of unauthorized file manipulation and potential execution of malicious code.
More Phoenix Contact CVEs
Sources
Originally found and disclosed by Nozomi, per the CVE Program record.