Description
The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.
Published: 2026-08-12
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Description The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.
Title Unauthenticated Buffer Overflow in PROFINET Service
First Time appeared Phoenix Contact
Phoenix Contact axc F 1152 Firmware
Phoenix Contact axc F 1252 Firmware
Phoenix Contact axc F 2152 Firmware
Phoenix Contact axc F 3152 Firmware
Phoenix Contact bpc 9102s Firmware
Phoenix Contact bpc 9202s Firmware
Phoenix Contact epc 1502 Firmware
Phoenix Contact epc 1522 Firmware
Phoenix Contact rfc 4072r Firmware
Phoenix Contact rfc 4072s Firmware
Phoenix Contact vl3 Upc 2440 Edge Firmware
Phoenix Contact vplcnext Control 1000 Firmware
Phoenix Contact vplcnext Control 2000 Firmware
Phoenix Contact vplcnext Control 3000 Firmware
Phoenix Contact vplcnext Control 500 Firmware
Weaknesses CWE-120
CPEs cpe:2.3:o:phoenix_contact:axc_f_1152_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:axc_f_1252_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:axc_f_2152_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:axc_f_3152_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:bpc_9102s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:bpc_9202s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:epc_1502_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:epc_1522_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:rfc_4072r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:rfc_4072s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:vl3_upc_2440_edge_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:vplcnext_control_1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:vplcnext_control_2000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:vplcnext_control_3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:vplcnext_control_500_firmware:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact axc F 1152 Firmware
Phoenix Contact axc F 1252 Firmware
Phoenix Contact axc F 2152 Firmware
Phoenix Contact axc F 3152 Firmware
Phoenix Contact bpc 9102s Firmware
Phoenix Contact bpc 9202s Firmware
Phoenix Contact epc 1502 Firmware
Phoenix Contact epc 1522 Firmware
Phoenix Contact rfc 4072r Firmware
Phoenix Contact rfc 4072s Firmware
Phoenix Contact vl3 Upc 2440 Edge Firmware
Phoenix Contact vplcnext Control 1000 Firmware
Phoenix Contact vplcnext Control 2000 Firmware
Phoenix Contact vplcnext Control 3000 Firmware
Phoenix Contact vplcnext Control 500 Firmware
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Axc F 1152 Firmware Axc F 1252 Firmware Axc F 2152 Firmware Axc F 3152 Firmware Bpc 9102s Firmware Bpc 9202s Firmware Epc 1502 Firmware Epc 1522 Firmware Rfc 4072r Firmware Rfc 4072s Firmware Vl3 Upc 2440 Edge Firmware Vplcnext Control 1000 Firmware Vplcnext Control 2000 Firmware Vplcnext Control 3000 Firmware Vplcnext Control 500 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-08-12T08:05:54.382Z

Reserved: 2025-04-16T11:18:45.761Z

Link: CVE-2025-41769

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T08:17:11.590

Modified: 2026-08-12T08:17:11.590

Link: CVE-2025-41769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:30:03Z

Weaknesses