Junglewise Threat Intelligence

CVE-2025-41669: Phoenix Contact PLCnext Control improper signature verification in WBM

CVE-2025-41669 · Severity: high · CVSS 8.8 · Published 2026-05-27

Technologies: Phoenix Contact AXC F 1152, Phoenix Contact EPC 1522. Vendors: Phoenix Contact.

Executive brief

Phoenix Contact PLCnext industrial controllers contain a vulnerability in their web management interface that allows users with low-level 'Engineer' privileges to install unauthorized applications. Because the system does not verify the authenticity of these apps, an attacker can install malicious software that takes full control of the device with root privileges. This could lead to a complete shutdown of industrial processes, data theft, or the manipulation of critical infrastructure controls.

Technical details

A vulnerability exists in the Web-based Management (WBM) component of Phoenix Contact PLCnext firmware due to improper verification of cryptographic signatures (CWE-347) during the APP installation process. A remote attacker authenticated with low-privileged 'Engineer' credentials can upload and install a manipulated APP package because the device fails to implement a data verification mechanism for store-downloaded apps. Successful exploitation allows the attacker to achieve arbitrary code execution with root privileges on the PLC device. This vulnerability affects multiple PLCnext Control models and is resolved in firmware version 2026.0.3.

Affected products

  • Phoenix Contact AXC F 1152 <2026.0.3
  • Phoenix Contact AXC F 1252 <2026.0.3
  • Phoenix Contact AXC F 2000 EA <2026.0.3
  • Phoenix Contact AXC F 2152 <2026.0.3
  • Phoenix Contact AXC F 3152 <2026.0.3
  • Phoenix Contact BPC 9102S <2026.0.3
  • Phoenix Contact EPC 1522 <2026.0.3
  • Phoenix Contact RFC 4072R <2026.0.3
  • Phoenix Contact RFC 4072S <2026.0.3
  • Phoenix Contact VL3 UPC 2440 EDGE <2026.0.3
  • Phoenix Contact VPLCNEXT CONTROL 1000 <2026.0.3
  • Phoenix Contact,versions: VPLCNEXT CONTROL 2000

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory
  • 2026-05-27: patched: Fixed in firmware version 2026.0.3

References

Related threats