Executive brief
Phoenix Contact PLCnext Control devices run industrial automation controllers that manage factory equipment and processes. These devices contain a buffer overflow vulnerability in their PROFINET networking service that can be exploited by attackers on the network without authentication. An attacker could reboot the device, causing production downtime, or execute arbitrary code to gain full control of the controller and the equipment it manages.
Technical details
The vulnerability is a buffer overflow in the PROFINET service of PLCnext firmware versions prior to 2026.0.3. The flaw exists in the default configuration and can be triggered by an unauthenticated remote attacker sending malformed PROFINET protocol packets over the network. Successful exploitation allows denial of service (device reboot) or remote code execution with full device privileges. The vulnerability is resolved in PLCnext firmware version 2026.0.3 and later. No public exploit code is currently known to be in active use.
Affected products
- Phoenix Contact PLCnext Control Catan C1 prior to 2026.0.3
- Phoenix Contact PLCnext Control EPC 1502 prior to 2026.0.3
- Phoenix Contact PLCnext Control EPC 1522 prior to 2026.0.3
- Phoenix Contact PLCnext Control AXC F 1152 prior to 2026.0.3
Timeline
- 2026-08-12: disclosed: Vulnerability publicly disclosed
- 2026-08-12: patched: Fix available in PLCnext firmware version 2026.0.3 and later