CVE-2025-25268: Unauthenticated Configuration Access via Exposed API Endpoint
An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25268?
CVE-2025-25268 is classified as a high severity vulnerability due to the potential for unauthorized access and modification of configurations.
How do I fix CVE-2025-25268?
To fix CVE-2025-25268, update the Phoenixcontact Charx Sec firmware to version 1.7.3 or later, which contains the necessary security patches.
What impact does CVE-2025-25268 have on affected systems?
CVE-2025-25268 allows unauthenticated adjacent attackers to modify configurations, leading to unauthorized read and write access.
Which Phoenixcontact products are affected by CVE-2025-25268?
CVE-2025-25268 affects the Phoenixcontact Charx Sec-3000, Charx Sec-3050, Charx Sec-3100, and Charx Sec-3150 firmware versions prior to 1.7.3.
Is CVE-2025-25268 exploitable remotely?
CVE-2025-25268 is not considered a remote vulnerability, as it requires an adjacent attacker to exploit the configuration modification.