CVE-2025-41668
8.8PHOENIX CONTACT · PLCnext Control devices (AXC F 1152, AXC F 2152, AXC F 3152, BPC 9102S, RFC 4072S)
A low privileged remote attacker can perform improper link resolution to gain arbitrary read, write, and execute access to files on Phoenix Contact PLCnext Control devices.
Executive summary
A critical file system vulnerability in Phoenix Contact PLCnext Control devices allows authenticated low privileged attackers to achieve full system control.
Vulnerability
This flaw stems from CWE-59, Improper Link Resolution Before File Access, which allows an authenticated attacker with low privileges to replace critical system files or folders used by the security-profile service.
Business impact
Successful exploitation grants an attacker the ability to read, modify, or execute arbitrary files on the affected industrial controllers. Given the CVSS score of 8.8, this represents a high risk of unauthorized system manipulation, potentially leading to operational disruption or the compromise of sensitive industrial process data.
Remediation
Immediate Action: Update all affected PLCnext Control devices to firmware version 2025.0.2 or later as specified in the vendor advisory.
Proactive Monitoring: Review system access logs for unusual file modification patterns or unauthorized attempts to access or replace configuration files within the security-profile directory.
Compensating Controls: Restrict network access to the management interfaces of these controllers to trusted administrative networks only, effectively reducing the attack surface for remote threats.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates immediate attention for all organizations utilizing the affected Phoenix Contact hardware. Administrators must prioritize the deployment of the 2025.0.2 firmware update to neutralize the risk of unauthorized system file manipulation and maintain the integrity of their industrial control environment.
More PHOENIX CONTACT CVEs
Sources
Originally found and disclosed by Nozomi, per the CVE Program record.