CVE-2025-41669
CVSS 8.8 HIGH: the Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device… EPSS 0.2% (12th percentile).
Vulnerabilities · 104 days ago
A low-privilege web account on a PLC should not be able to reach the trust checks that protect the controller itself. Here, that boundary fails, so an Engineer role can escalate to root and get to the material used to validate or sign control logic; cleanup of the original account does not undo that kind of device-level tampering.
Nozomi says the issue affects Phoenix Contact PLCnext AXC F 3152 firmware 2024.0.6, and Phoenix Contact says multiple PLCnext models are affected. The finding sits in the web interface and the vendor has already released updated firmware, which matters for OT teams because the blast radius is not just one controller model but any PLCnext or CODESYS-based device that stores trust on-box and exposes a management role.
CVSS 8.8 HIGH: the Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device… EPSS 0.2% (12th percentile).
1 source covering this story
Nozomi warns that privilege-escalation flaws in Phoenix Contact PLCnext controllers could enable attackers to gain root access.
Part of the PlainSec briefing for 2026-06-02