Description
The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.
Published: 2026-05-27
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Web‑based Management interface of Phoenix Contact PLC devices, where an Engineer user can install application packages from the PLCnext Store without any data verification. This flaw permits the user to load a malicious APP, leading to arbitrary code execution with root privileges on the device. The weakness is a failure to validate data authenticity, corresponding to CWE‑347. The resulting impact includes potential compromise of confidentiality, integrity, and availability of the PLCnext Control system.

Affected Systems

The affected devices are all Phoenix Contact PLCnext Control units, specifically the AXC F 1152, AXC F 1252, AXC F 2000 EA, AXC F 2152, AXC F 3152, BPC 9102S, EPC 1522, RFC 4072R, RFC 4072S, VL3 UPC 2440 EDGE, VPLCNEXT CONTROL 1000, 2000, 3000, and 500 series. No specific firmware versions are enumerated in the advisory, so any firmware that supports the Web‑based Management interface may be susceptible.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score is not available, which does not provide insight into current exploitation probability. The advisory is not listed in CISA’s KEV catalog, suggesting it is not yet a known exploited vulnerability. The likely attack vector is remote exploitation through the web interface; an attacker requires only a low‑privilege Engineer account but can achieve root‑level code execution once a malicious app is installed. No additional system configuration prerequisites are mentioned in the advisory.

Generated by OpenCVE AI on May 27, 2026 at 09:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest firmware or security patch that implements data verification for application installations.
  • Disable or restrict the ability to install apps from the PLCnext Store until verification can be enforced, or use local installation with signed packages only.
  • Restrict Web‑based Management access to trusted internal networks and enforce multi‑factor authentication for Engineer accounts.
  • Apply strict input validation for app uploads to ensure payload integrity (mitigating CWE‑347).

Generated by OpenCVE AI on May 27, 2026 at 09:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 27 May 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.
Title Insufficient Verification of Data Authenticity
First Time appeared Phoenix Contact
Phoenix Contact axc F 1152
Phoenix Contact axc F 1252
Phoenix Contact axc F 2000 Ea
Phoenix Contact axc F 2152
Phoenix Contact axc F 3152
Phoenix Contact bpc 9102s
Phoenix Contact epc 1522
Phoenix Contact rfc 4072r
Phoenix Contact rfc 4072s
Phoenix Contact vl3 Upc 2440 Edge
Phoenix Contact vplcnext Control 1000
Phoenix Contact vplcnext Control 2000
Phoenix Contact vplcnext Control 3000
Phoenix Contact vplcnext Control 500
Weaknesses CWE-347
CPEs cpe:2.3:a:phoenix_contact:axc_f_1152:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:axc_f_1252:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:axc_f_2000_ea:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:axc_f_2152:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:axc_f_3152:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:bpc_9102s:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:epc_1522:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:rfc_4072r:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:rfc_4072s:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:vl3_upc_2440_edge:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:vplcnext_control_1000:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:vplcnext_control_2000:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:vplcnext_control_3000:*:*:*:*:*:*:*:*
cpe:2.3:a:phoenix_contact:vplcnext_control_500:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact axc F 1152
Phoenix Contact axc F 1252
Phoenix Contact axc F 2000 Ea
Phoenix Contact axc F 2152
Phoenix Contact axc F 3152
Phoenix Contact bpc 9102s
Phoenix Contact epc 1522
Phoenix Contact rfc 4072r
Phoenix Contact rfc 4072s
Phoenix Contact vl3 Upc 2440 Edge
Phoenix Contact vplcnext Control 1000
Phoenix Contact vplcnext Control 2000
Phoenix Contact vplcnext Control 3000
Phoenix Contact vplcnext Control 500
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Axc F 1152 Axc F 1252 Axc F 2000 Ea Axc F 2152 Axc F 3152 Bpc 9102s Epc 1522 Rfc 4072r Rfc 4072s Vl3 Upc 2440 Edge Vplcnext Control 1000 Vplcnext Control 2000 Vplcnext Control 3000 Vplcnext Control 500
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-05-27T12:04:07.823Z

Reserved: 2025-04-16T11:17:48.308Z

Link: CVE-2025-41669

cve-icon Vulnrichment

Updated: 2026-05-27T12:04:03.164Z

cve-icon NVD

Status : Deferred

Published: 2026-05-27T08:16:39.710

Modified: 2026-05-27T14:53:22.863

Link: CVE-2025-41669

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T11:00:12Z

Weaknesses