CVE-2025-41769
9.8Phoenix Contact · AXC F 1152
A buffer overflow vulnerability in the PROFINET service of Phoenix Contact controllers allows unauthenticated remote attackers to cause a device reboot or execute arbitrary code.
Executive summary
Phoenix Contact controllers are susceptible to a critical buffer overflow vulnerability in their PROFINET service, which can be exploited by unauthenticated attackers to gain code execution.
Vulnerability
The PROFINET service contains a classic buffer overflow (CWE-120) that permits an unauthenticated remote attacker to overflow memory buffers, leading to either a denial of service (reboot) or arbitrary code execution.
Business impact
Exploitation of this vulnerability in industrial control systems can lead to unauthorized manipulation of physical processes, operational downtime, or the loss of sensitive control logic. Given the CVSS score of 9.8, this poses a severe risk to the availability and safety of industrial infrastructure.
Remediation
Immediate Action: Update the affected Phoenix Contact devices to firmware version 2026.0.3 or later as specified by the vendor.
Proactive Monitoring: Monitor industrial network traffic for malformed PROFINET packets or unexpected device reboots.
Compensating Controls: Use industrial firewalls to isolate PROFINET traffic to trusted segments and disable unnecessary services on the controllers.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the critical impact on operational technology, organizations should apply the provided firmware updates as part of their next scheduled maintenance window or sooner if the devices are exposed to untrusted networks. Immediate action is required to ensure the security and stability of the affected controllers.