CVE-2025-41771
SQL injection
Record summary
CVE-2025-41771 has a selected CVSS score of 5.3 (medium).
Description
An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List
Affected products and versions
Showing 12 of 17| Product | Source | Version range | Status |
|---|---|---|---|
AXC F 1152Browse Phoenix Contact / AXC F 1152Default status: unaffected | CVE List | 2019.0.4 to < 2026.0.3 | affected |
AXC F 1252Browse Phoenix Contact / AXC F 1252Default status: unaffected | CVE List | 2019.0.4 to < 2026.0.3 | affected |
AXC F 2000 EABrowse Phoenix Contact / AXC F 2000 EADefault status: unaffected | CVE List | 2019.0.4 to < 2026.0.3 | affected |
AXC F 2152Browse Phoenix Contact / AXC F 2152Default status: unaffected | CVE List | 2019.0.4 to < 2026.0.3 | affected |
AXC F 3152Browse Phoenix Contact / AXC F 3152Default status: unaffected | CVE List | 2019.0.4 to < 2026.0.3 | affected |
BPC 9102SBrowse Phoenix Contact / BPC 9102SDefault status: unaffected | CVE List | 2019.0.4 to < 2026.0.3 | affected |
BPC 9202SBrowse Phoenix Contact / BPC 9202SDefault status: unaffected | CVE List | 2019.0.4 to < 2026.0.3 | affected |
Default status: unaffected | CVE List | 2019.0.4 to < 2026.0.3 | affected |
Default status: unaffected | CVE List | 2019.0.4 to < 2026.0.3 | affected |
Default status: unaffected | CVE List | 2019.0.4 to < 2026.0.3 | affected |
RFC 4072RBrowse Phoenix Contact / RFC 4072RDefault status: unaffected | CVE List | 2019.0.4 to < 2026.0.3 | affected |
RFC 4072SBrowse Phoenix Contact / RFC 4072SDefault status: unaffected | CVE List | 2019.0.4 to < 2026.0.3 | affected |