CVE-2025-41668

8.8

PHOENIX CONTACT · PLCnext Control devices (AXC F 1152, AXC F 2152, AXC F 3152, BPC 9102S, RFC 4072S)

A low privileged remote attacker can perform improper link resolution to gain arbitrary read, write, and execute access to files on Phoenix Contact PLCnext Control devices.

Executive summary

A critical file system vulnerability in Phoenix Contact PLCnext Control devices allows authenticated low privileged attackers to achieve full system control.

Vulnerability

This flaw stems from CWE-59, Improper Link Resolution Before File Access, which allows an authenticated attacker with low privileges to replace critical system files or folders used by the security-profile service.

Business impact

Successful exploitation grants an attacker the ability to read, modify, or execute arbitrary files on the affected industrial controllers. Given the CVSS score of 8.8, this represents a high risk of unauthorized system manipulation, potentially leading to operational disruption or the compromise of sensitive industrial process data.

Remediation

Immediate Action: Update all affected PLCnext Control devices to firmware version 2025.0.2 or later as specified in the vendor advisory.

Proactive Monitoring: Review system access logs for unusual file modification patterns or unauthorized attempts to access or replace configuration files within the security-profile directory.

Compensating Controls: Restrict network access to the management interfaces of these controllers to trusted administrative networks only, effectively reducing the attack surface for remote threats.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate attention for all organizations utilizing the affected Phoenix Contact hardware. Administrators must prioritize the deployment of the 2025.0.2 firmware update to neutralize the risk of unauthorized system file manipulation and maintain the integrity of their industrial control environment.

More PHOENIX CONTACT CVEs

Sources

Originally found and disclosed by Nozomi, per the CVE Program record.