Junglewise Threat Intelligence

CVE-2025-41770: Phoenix Contact PLCnext denial-of-service in engineer interface

CVE-2025-41770 · Severity: high · CVSS 7.5 · Published 2026-08-12

Technologies: Phoenix Contact AXC F 1152, Phoenix Contact EPC 1522. Vendors: Phoenix Contact.

Executive brief

Phoenix Contact PLCnext is an industrial control system platform used to program and manage programmable logic controllers in manufacturing and infrastructure environments. An unauthenticated attacker can remotely crash the device's engineering communication service, preventing legitimate operators from accessing or controlling the device until manual service restart. This disruption can halt production, compromise operational safety, and impact facility availability.

Technical details

An unauthenticated denial-of-service vulnerability exists in the PLCnext Engineer communication interface due to improper input validation. The network-facing interface accepts malicious requests from remote attackers without requiring authentication, allowing them to trigger a crash of the PLCnext service. Successful exploitation interrupts all client communication until the service is manually restarted, causing loss of device availability. The vulnerability affects PLCnext firmware versions prior to 2026.0.3, and the vendor has released a patched firmware version that addresses this and related issues.

Affected products

  • Phoenix Contact Catan C1 before 2026.0.3
  • Phoenix Contact EPC 1502 before 2026.0.3
  • Phoenix Contact EPC 1522 before 2026.0.3
  • Phoenix Contact AXC F 1152 before 2026.0.3

Timeline

  • 2026-08-12: disclosed: Public disclosure via NVD and CERT@VDE
  • 2026-08-12: patched: Phoenix Contact PLCnext firmware version 2026.0.3 or later addresses the vulnerability

References

Related threats