Phoenix Contact Vulnerabilities and Affected Products
Vulnerabilities associated with FL SWITCH 2005.
Products
Clear product- CHARX SEC-300051 vulnerabilities
- CHARX SEC-305051 vulnerabilities
- CHARX SEC-310051 vulnerabilities
- CHARX SEC-315051 vulnerabilities
- FL NAT 200822 vulnerabilities
- FL NAT 220822 vulnerabilities
- FL NAT 2304-2GC-2SFP22 vulnerabilities
- FL SWITCH 200522 vulnerabilities
- FL SWITCH 200822 vulnerabilities
- FL SWITCH 2008F22 vulnerabilities
- FL SWITCH 201622 vulnerabilities
- FL SWITCH 210522 vulnerabilities
- FL SWITCH 210822 vulnerabilities
- FL SWITCH 211622 vulnerabilities
- FL SWITCH 2204-2TC-2SFX22 vulnerabilities
- FL SWITCH 220522 vulnerabilities
- FL SWITCH 2206-2FX22 vulnerabilities
- FL SWITCH 2206-2FX SM22 vulnerabilities
- FL SWITCH 2206-2FX SM ST22 vulnerabilities
- FL SWITCH 2206-2FX ST22 vulnerabilities
- FL SWITCH 2206-2SFX22 vulnerabilities
- FL SWITCH 2206-2SFX PN22 vulnerabilities
- FL SWITCH 2206C-2FX22 vulnerabilities
- FL SWITCH 2207-FX22 vulnerabilities
- FL SWITCH 2207-FX SM22 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-22323HIGH | Cross‑Site Request Forgery in Link Aggregation ConfigurationA CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick authenticated users into sending unauthorized POST requests to the device by luring them to a malicious webpage. This can silently alter the device’s configuration without the victim’s knowledge or consent. Availability impact was set to low because after a successful attack the device will automatically recover without external intervention. CWE-352Mar 18, 2026 | CVSS7.1v3.1 | EPSS0.178% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22322HIGH | Stored Cross‑Site Scripting in Link Aggregation Name HandlingA stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to create a trunk entry containing malicious HTML/JavaScript code. When the affected page is viewed, the injected script executes in the context of the victim’s browser, enabling unauthorized actions such as interface manipulation. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticat… CWE-79Mar 18, 2026 | CVSS7.1v3.1 | EPSS0.253% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22321MEDIUM | Stack-Based Buffer Overflow in CLI Login Username Handling over CLIA stack-based buffer overflow in the device's Telnet/SSH CLI login routine occurs when a unauthenticated attacker send an oversized or unexpected username input. An overflow condition crashes the thread handling the login attempt, forcing the session to close. Because other CLI sessions remain unaffected, the impact is limited to a low‑severity availability disruption. CWE-121Mar 18, 2026 | CVSS5.3v3.1 | EPSS0.366% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22320MEDIUM | Stack-Based Buffer Overflow in TFTP File-Transfer Command Handling over CLIA stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Telnet/SSH access to trigger memory corruption by supplying unexpected or oversized filename input. Exploitation results in the corruption of the internal buffer, causing the CLI and web dashboard to become unavailable and leading to a denial of service. CWE-121Mar 18, 2026 | CVSS6.5v3.1 | EPSS0.317% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22319MEDIUM | Stack-Based Buffer Overflow in File Install Parameter HandlingA stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send oversized POST parameters that overflow a fixed-size stack buffer within an internal process, resulting in a DoS attack. CWE-121Mar 18, 2026 | CVSS4.9v3.1 | EPSS0.339% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22318MEDIUM | Stack-Based Buffer Overflow in File Transfer Parameter HandlingA stack-based buffer overflow vulnerability in the device's file transfer parameter workflow allows a high-privileged attacker to send oversized POST parameters, causing memory corruption in an internal process, resulting in a DoS attack. CWE-121Mar 18, 2026 | CVSS4.9v3.1 | EPSS0.339% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22317HIGH | Command Injection Vulnerability in Root CA Certificate Transfer WorkflowA command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged attacker to send crafted HTTP POST requests that result in arbitrary command execution on the underlying Linux OS with root privileges. CWE-77Mar 18, 2026 | CVSS7.2v3.1 | EPSS0.999% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22316MEDIUM | Buffer Overflow using TFTP FilenameA remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request to trigger a stack-based Buffer Overflow, resulting in a DoS attack. CWE-121Mar 18, 2026 | CVSS6.5v3.1 | EPSS0.378% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41693MEDIUM | Authenticated Denial-of-Service via SSHA low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses resources which leads to a reduced performance of the management functions. Switching functionality is not affected. CWE-770Dec 9, 2025 | CVSS4.3v3.1 | EPSS0.504% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41696MEDIUM | Hardcoded User PasswordAn attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device. CWE-798Dec 9, 2025 | CVSS4.6v3.1 | EPSS0.206% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41694MEDIUM | Authenticated Denial-of-Service via WebshellA low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block until it receives more data, resulting in a DoS condition of the websserver. CWE-770Dec 9, 2025 | CVSS6.5v3.1 | EPSS0.471% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41692MEDIUM | Weak/Predictable root PasswordA high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm. CWE-916Dec 9, 2025 | CVSS6.8v3.1 | EPSS0.29% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41697MEDIUM | Shell access to UART ConsoleAn attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692. CWE-1299Dec 9, 2025 | CVSS6.8v3.1 | EPSS0.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41695HIGH | Reflected XSS vulnerability in dyn_conn.phpAn XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is … CWE-79Dec 9, 2025 | CVSS7.1v3.1 | EPSS0.66% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41745HIGH | Reflected XSS vulnerability in pxc_portCntr2.phpAn XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cooki… CWE-79Dec 9, 2025 | CVSS7.1v3.1 | EPSS0.653% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41746HIGH | Reflected XSS vulnerability in pxc_portSecCfg.phpAn XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cook… CWE-79Dec 9, 2025 | CVSS7.1v3.1 | EPSS9.77% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41747HIGH | Reflected XSS vulnerability in pxc_vlanIntfCfg.phpAn XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session coo… CWE-79Dec 9, 2025 | CVSS7.1v3.1 | EPSS9.77% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41748HIGH | Reflected XSS vulnerability in pxc_Dot1xCfg.phpAn XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is… CWE-79Dec 9, 2025 | CVSS7.1v3.1 | EPSS9.77% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41749HIGH | Reflected XSS vulnerability in port_util.phpAn XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is se… CWE-79Dec 9, 2025 | CVSS7.1v3.1 | EPSS0.653% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41750HIGH | Reflected XSS vulnerability in pxc_PortCfg.phpAn XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is … CWE-79Dec 9, 2025 | CVSS7.1v3.1 | EPSS9.77% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41751HIGH | Reflected XSS vulnerability in pxc_portCntr.phpAn XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is… CWE-79Dec 9, 2025 | CVSS7.1v3.1 | EPSS9.77% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41752HIGH | Reflected XSS vulnerability in pxc_portSfp.phpAn XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is … CWE-79Dec 9, 2025 | CVSS7.1v3.1 | EPSS9.77% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |