PT-2026-71038 · Phoenix Contact · Axc F 1152+16

·

CVE-2025-41771

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description An authenticated attacker with low privileges can access an endpoint in the controller web interface that is vulnerable to SQL injection. This issue affects a SQLite database used exclusively for storing notification messages, limiting the impact to the system notification functionality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-41771

Affected Products

Axc F 1152
Axc F 1252
Axc F 2000 Ea
Axc F 2152
Axc F 3152
Bpc 9102S
Bpc 9202S
Catan C1
Epc 1502
Epc 1522
Rfc 4072R
Rfc 4072S
Vl3 Upc 2440 Edge
Vplcnext Control 1000
Vplcnext Control 2000
Vplcnext Control 3000
Vplcnext Control 500