CVE-2025-41667

8.8

Phoenix Contact · AXC F 1152, AXC F 2152, AXC F 3152, BPC 9102S, RFC 4072S

A low privileged remote attacker can exploit improper link resolution in the arp-preinit script to gain arbitrary read, write, and execute access to files on the affected Phoenix Contact devices.

Executive summary

A critical file system vulnerability in multiple Phoenix Contact controllers allows low privileged remote attackers to gain full system-level access via file replacement.

Vulnerability

This flaw involves improper link resolution before file access (CWE-59) within the arp-preinit script. A low privileged, authenticated remote attacker can manipulate file links to achieve unauthorized read, write, and execute permissions on the target device.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its high potential for total system compromise. Successful exploitation grants an attacker full control over the controller, which could result in severe operational disruption, the manipulation of industrial control processes, or the exfiltration of sensitive configuration data.

Remediation

Immediate Action: Update the affected Phoenix Contact devices to firmware version 2025.0.2 or later as specified in the vendor advisory.

Proactive Monitoring: Review system logs for unauthorized file modification attempts or anomalous activity associated with the arp-preinit script execution.

Compensating Controls: Restrict network access to the management interfaces of these devices to trusted administrative subnets to minimize the risk of unauthorized remote access.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for complete system compromise on critical industrial control hardware, administrators must prioritize the update to firmware version 2025.0.2. Organizations should verify that all listed controller models are patched across their environment to eliminate the risk of privilege escalation and unauthorized file access.

More Phoenix Contact CVEs

Sources

Originally found and disclosed by Nozomi, per the CVE Program record.