CVE-2026-22322
7.1Phoenix Contact · FL SWITCH 2000 Series
A stored cross-site scripting (XSS) vulnerability in the Phoenix Contact FL SWITCH configuration interface allows unauthenticated remote attackers to execute malicious scripts in a victim's browser.
Executive summary
An unauthenticated remote attacker can inject malicious scripts into the Link Aggregation configuration of various Phoenix Contact FL SWITCH models, posing a risk of unauthorized interface manipulation.
Vulnerability
This is a stored cross-site scripting (XSS) vulnerability residing in the Link Aggregation configuration interface. An unauthenticated attacker can inject arbitrary HTML or JavaScript, which executes when an administrator views the affected page.
Business impact
Successful exploitation allows an attacker to perform unauthorized actions within the context of the administrator's browser session. While the httpOnly flag prevents session cookie theft, the ability to manipulate the network switch configuration could lead to service disruption or unauthorized changes to industrial network traffic routing. Given the CVSS score of 7.1, this is classified as a High severity issue requiring prompt attention to maintain operational integrity.
Remediation
Immediate Action: Update all affected Phoenix Contact FL SWITCH devices to firmware version 3.53 or later as specified in the vendor advisory.
Proactive Monitoring: Monitor device configuration logs for unexpected changes to Link Aggregation settings or signs of unauthorized access attempts.
Compensating Controls: Restrict access to the device management interface to trusted management subnets and employ a Web Application Firewall (WAF) to filter malicious script payloads where applicable.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a significant risk to industrial control environments by allowing unauthorized configuration changes via script injection. Administrators should prioritize the deployment of the vendor-provided firmware update across all affected switch models to neutralize the attack vector. Failure to patch may leave the device interface susceptible to exploitation by remote actors.
More Phoenix Contact CVEs
Sources
Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, per the CVE Program record.