CVE-2025-25269: Local Privilege Escalation via Unauthenticated Command Injection
Published Jul 8, 2025
·Updated
An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.
Affected Software
8 affected components
All of the following
Phoenixcontact Charx Sec-3000 Firmware<1.7.3
Phoenixcontact Charx Sec-3000
All of the following
Phoenixcontact Charx Sec-3050 Firmware<1.7.3
Phoenixcontact Charx Sec-3050
All of the following
Phoenixcontact Charx Sec-3100 Firmware<1.7.3
Phoenixcontact Charx Sec-3100
All of the following
Phoenixcontact Charx Sec-3150 Firmware<1.7.3
Phoenixcontact Charx Sec-3150
Event History
Jul 8, 2025
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25269?
CVE-2025-25269 has a high severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2025-25269?
To fix CVE-2025-25269, users should upgrade to version 1.7.3 or later of the affected firmware.
3
What products are affected by CVE-2025-25269?
CVE-2025-25269 affects Phoenixcontact Charx Sec-3000, Charx Sec-3050, Charx Sec-3100, and Charx Sec-3150 firmware versions prior to 1.7.3.
4
Can CVE-2025-25269 be exploited remotely?
CVE-2025-25269 cannot be exploited remotely as it requires local access by an unauthenticated attacker.
5
What are the risks associated with CVE-2025-25269?
The risks associated with CVE-2025-25269 include unauthorized command execution and potential full system compromise.