CVE-2026-22323

7.1

Phoenix Contact · FL SWITCH 2000 Series

A Cross-Site Request Forgery (CSRF) vulnerability in the Link Aggregation configuration interface allows remote attackers to execute unauthorized POST requests on affected Phoenix Contact switches.

Executive summary

A Cross-Site Request Forgery vulnerability in Phoenix Contact FL SWITCH 2000 series devices allows remote attackers to silently modify device configurations by tricking authenticated users.

Vulnerability

The flaw is a Cross-Site Request Forgery (CWE-352) residing in the Link Aggregation configuration interface. While the attacker is unauthenticated, they rely on social engineering to trick an authenticated administrator into executing unauthorized state-changing POST requests.

Business impact

The ability for an unauthorized party to modify network switch configurations poses a significant risk to industrial and enterprise infrastructure. Successful exploitation could lead to unauthorized network segmentation changes, denial of service, or the disruption of critical traffic flows, resulting in operational downtime and potential security policy bypasses. With a CVSS score of 7.1, this high-severity vulnerability requires immediate attention to prevent unauthorized configuration changes.

Remediation

Immediate Action: Update all affected Phoenix Contact FL SWITCH devices to firmware version 3.53 or higher to patch the configuration interface.

Proactive Monitoring: Audit network logs for unexpected configuration changes or administrative actions originating from unauthorized sources or unusual times.

Compensating Controls: Implement strict network access control lists to limit management interface access to trusted administrative workstations only, reducing the likelihood of a successful CSRF attack.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the potential for unauthorized modification of network infrastructure, security teams should prioritize the firmware update for all identified Phoenix Contact switches. Until patching is complete, ensure administrative interfaces are not exposed to the public internet and educate users against clicking suspicious links while logged into device management consoles.

More Phoenix Contact CVEs

Sources

Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, per the CVE Program record.