Executive brief
Phoenix Contact PLCnext is an industrial control platform used in manufacturing and critical infrastructure automation. An authenticated attacker with low privileges can execute SQL injection attacks against the notification system, potentially compromising the integrity of alerts and system monitoring. While the immediate impact is limited to notification functionality, SQL injection in industrial systems poses risk to operational visibility and could serve as a foothold for further attacks.
Technical details
The vulnerability is an SQL injection flaw in an authenticated web interface endpoint of the PLCnext controller. The vulnerable component is a SQLite database used exclusively for storing notification messages. An attacker with low-privilege authenticated access can inject malicious SQL queries through improper input validation on this endpoint. The attack requires prior authentication and network access to the web interface; unauthenticated remote exploitation is not possible. Successful exploitation allows an attacker to read, modify, or delete notification records. Phoenix Contact has released firmware version 2026.0.3 and later to address this issue.
Affected products
- Phoenix Contact PLCnext prior to 2026.0.3
- Phoenix Contact Catan C1 <UNKNOWN>
- Phoenix Contact EPC 1502 <UNKNOWN>
- Phoenix Contact EPC 1522 <UNKNOWN>
- Phoenix Contact AXC F 1152 <UNKNOWN>
Timeline
- 2026-08-12: disclosed: PCSA-2025-00009 / VDE-2025-056 published
- 2026-08-12: patched: PLCnext firmware 2026.0.3 released