CVE-2026-22320

MEDIUM

Stack-Based Buffer Overflow in TFTP File-Transfer Command Handling over CLI

Title source: cna
STIX 2.1

Description

A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Telnet/SSH access to trigger memory corruption by supplying unexpected or oversized filename input. Exploitation results in the corruption of the internal buffer, causing the CLI and web dashboard to become unavailable and leading to a denial of service.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0032
EPSS Percentile 23.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-121
Status published
Products (50)
Phoenix Contact/FL NAT 2008 0.0.0 - 3.53
Phoenix Contact/FL NAT 2208 0.0.0 - 3.53
Phoenix Contact/FL NAT 2304-2GC-2SFP 0.0.0 - 3.53
Phoenix Contact/FL SWITCH 2005 0.0.0 - 3.53
Phoenix Contact/FL SWITCH 2008 0.0.0 - 3.53
Phoenix Contact/FL SWITCH 2008F 0.0.0 - 3.53
Phoenix Contact/FL SWITCH 2016 0.0.0 - 3.53
Phoenix Contact/FL SWITCH 2105 0.0.0 - 3.53
Phoenix Contact/FL SWITCH 2108 0.0.0 - 3.53
Phoenix Contact/FL SWITCH 2116 0.0.0 - 3.53
... and 40 more
Published Mar 18, 2026
Tracked Since Mar 18, 2026