Executive brief
A vulnerability in Phoenix Contact PLCnext controllers allows a local user with low privileges to gain full administrative control over the device. By modifying specific configuration files in areas of the system that are not properly protected, an attacker can trick high-priority system services into executing unauthorized actions. This could lead to a complete takeover of the industrial controller, potentially disrupting manufacturing processes or compromising sensitive operational data.
Technical details
The vulnerability is classified as an Uncontrolled Search Path Element (CWE-427) within the PLCnext firmware. It occurs because a privileged system service processes configuration or application-related data from filesystem locations that permit write access to low-privileged users. An attacker with local authenticated access can manipulate these files to influence the service's execution flow. Because the service runs with elevated permissions, this manipulation enables the attacker to achieve local privilege escalation (LPE) and potentially execute arbitrary code with root privileges. The issue is resolved in firmware version 2026.0.3.
Affected products
- Phoenix Contact AXC F 1152 <2026.0.3
- Phoenix Contact AXC F 1252 <2026.0.3
- Phoenix Contact AXC F 2000 EA <2026.0.3
- Phoenix Contact AXC F 2152 <2026.0.3
- Phoenix Contact AXC F 3152 <2026.0.3
- Phoenix Contact BPC 9102S <2026.0.3
- Phoenix Contact EPC 1522 <2026.0.3
- Phoenix Contact RFC 4072R <2026.0.3
- Phoenix Contact RFC 4072S <2026.0.3
- Phoenix Contact VL3 UPC 2440 EDGE <2026.0.3
- Phoenix Contact VPLCNEXT CONTROL 1000 <2026.0.3
- Phoenix Contact VPLCNEXT CONTROL 2000 <2026.0.3
- Phoenix Contact,versions: VPLCNEXT CONTROL 3000 <2026.0.3
- Phoenix Contact VPLCNEXT CONTROL 500 <2026.0.3
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory
- 2026-05-27: patched: Fixed in firmware version 2026.0.3