Description
An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.
Published: 2026-08-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a classic SQL injection flaw that can be exploited through an authenticated web interface endpoint on Phoenix Contact controllers. The flaw allows an attacker with low‑privilege credentials to inject arbitrary SQL into a SQLite database used solely for storing notification messages. The result is that the attacker can read, modify, or delete notification data, which could mislead system operators or disrupt notification flow but does not compromise other device functions or data.

Affected Systems

The vulnerability affects a range of Phoenix Contact industrial controllers and edge devices, including models such as AXC F 1152, AXC F 1252, AXC F 2000 EA, AXC F 2152, AXC F 3152, BPC 9102S, BPC 9202S, Catan C1, EPC 1502, EPC 1522, RFC 4072R, RFC 4072S, VL3 UPC 2440 EDGE, VPLCNext Control 1000, 2000, 3000, and 500. No specific firmware revision numbers are listed, so all currently installed firmware versions of these devices are considered vulnerable until a patch is applied.

Risk and Exploitability

The CVSS base score of 5.3 indicates a medium risk, and the EPSS score is not available, suggesting limited public exploitation data. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed large‑scale attacks. Exploitation requires valid credentials, but low‑privilege users may exist by default or through mis‑management. Until a vendor fix is issued, the primary attack surface is the web interface, which should be isolated to trusted networks or secured using multi‑factor authentication to reduce risk.

Generated by OpenCVE AI on August 12, 2026 at 12:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued firmware update that addresses the SQL injection issue when it becomes available.
  • Limit access to the controller’s web interface to trusted internal networks, and consider disabling the endpoint if not required.
  • Enforce strong authentication, such as multi‑factor authentication, and restrict the use of low‑privilege accounts to the minimum necessary functions.
  • Monitor web interface logs for suspicious query activity and anomalous notification modifications.

Generated by OpenCVE AI on August 12, 2026 at 12:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Description An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.
Title SQL injection
First Time appeared Phoenix Contact
Phoenix Contact axc F 1152 Firmware
Phoenix Contact axc F 1252 Firmware
Phoenix Contact axc F 2000 Ea Firmware
Phoenix Contact axc F 2152 Firmware
Phoenix Contact axc F 3152 Firmware
Phoenix Contact bpc 9102s Firmware
Phoenix Contact bpc 9202s Firmware
Phoenix Contact catan C1 Firmware
Phoenix Contact epc 1502 Firmware
Phoenix Contact epc 1522 Firmware
Phoenix Contact rfc 4072r Firmware
Phoenix Contact rfc 4072s Firmware
Phoenix Contact vl3 Upc 2440 Edge Firmware
Phoenix Contact vplcnext Control 1000 Firmware
Phoenix Contact vplcnext Control 2000 Firmware
Phoenix Contact vplcnext Control 3000 Firmware
Phoenix Contact vplcnext Control 500 Firmware
Weaknesses CWE-89
CPEs cpe:2.3:o:phoenix_contact:axc_f_1152_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:axc_f_1252_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:axc_f_2000_ea_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:axc_f_2152_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:axc_f_3152_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:bpc_9102s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:bpc_9202s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:catan_c1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:epc_1502_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:epc_1522_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:rfc_4072r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:rfc_4072s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:vl3_upc_2440_edge_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:vplcnext_control_1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:vplcnext_control_2000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:vplcnext_control_3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:vplcnext_control_500_firmware:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact axc F 1152 Firmware
Phoenix Contact axc F 1252 Firmware
Phoenix Contact axc F 2000 Ea Firmware
Phoenix Contact axc F 2152 Firmware
Phoenix Contact axc F 3152 Firmware
Phoenix Contact bpc 9102s Firmware
Phoenix Contact bpc 9202s Firmware
Phoenix Contact catan C1 Firmware
Phoenix Contact epc 1502 Firmware
Phoenix Contact epc 1522 Firmware
Phoenix Contact rfc 4072r Firmware
Phoenix Contact rfc 4072s Firmware
Phoenix Contact vl3 Upc 2440 Edge Firmware
Phoenix Contact vplcnext Control 1000 Firmware
Phoenix Contact vplcnext Control 2000 Firmware
Phoenix Contact vplcnext Control 3000 Firmware
Phoenix Contact vplcnext Control 500 Firmware
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Axc F 1152 Firmware Axc F 1252 Firmware Axc F 2000 Ea Firmware Axc F 2152 Firmware Axc F 3152 Firmware Bpc 9102s Firmware Bpc 9202s Firmware Catan C1 Firmware Epc 1502 Firmware Epc 1522 Firmware Rfc 4072r Firmware Rfc 4072s Firmware Vl3 Upc 2440 Edge Firmware Vplcnext Control 1000 Firmware Vplcnext Control 2000 Firmware Vplcnext Control 3000 Firmware Vplcnext Control 500 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-08-12T12:32:06.185Z

Reserved: 2025-04-16T11:18:45.761Z

Link: CVE-2025-41771

cve-icon Vulnrichment

Updated: 2026-08-12T12:32:01.648Z

cve-icon NVD

Status : Received

Published: 2026-08-12T08:17:12.130

Modified: 2026-08-12T13:17:18.880

Link: CVE-2025-41771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:15:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')