CVE-2026-22317

7.2

Phoenix Contact · FL SWITCH 2000 Series

A command injection vulnerability in the Root CA certificate transfer workflow of Phoenix Contact FL SWITCH devices allows arbitrary command execution with root privileges.

Executive summary

A high-severity command injection vulnerability in Phoenix Contact FL SWITCH 2000 series devices allows authenticated attackers to achieve full system compromise.

Vulnerability

This vulnerability is a command injection flaw (CWE-77) triggered via the Root CA certificate transfer workflow. An attacker with high-level administrative privileges can send crafted HTTP POST requests to execute arbitrary commands on the underlying Linux operating system with root-level permissions.

Business impact

The ability to execute arbitrary commands as root grants an attacker complete control over the affected industrial network switch. Successful exploitation could lead to unauthorized network traffic interception, disruption of critical infrastructure operations, or use of the device as a pivot point for lateral movement within the production environment. Given the CVSS score of 7.2, this represents a significant risk to operational integrity and security.

Remediation

Immediate Action: Update the firmware of all affected Phoenix Contact FL SWITCH devices to version 3.53 or later as specified in the vendor advisory.

Proactive Monitoring: Review device access logs for suspicious HTTP POST requests directed toward certificate management endpoints or unauthorized configuration changes.

Compensating Controls: Restrict management access to the device to a dedicated, isolated management network and utilize network segmentation to limit the exposure of the administrative interface.

Exploitation status

Public Exploit Available: No (Exploit available: false)

Analyst recommendation

Organizations utilizing affected Phoenix Contact hardware must prioritize firmware updates to version 3.53 to eliminate this command injection vector. Due to the potential for full system control and the critical nature of these devices in industrial settings, testing and deployment of these updates should be scheduled within the next standard maintenance window to mitigate the risk of unauthorized administrative abuse.

More Phoenix Contact CVEs

Sources

Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, per the CVE Program record.