CVE-2025-25270: Remote Code Execution via Unauthenticated Configuration Manipulation
An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25270?
CVE-2025-25270 is classified as a critical vulnerability due to its potential for remote code execution as root by unauthenticated attackers.
How do I fix CVE-2025-25270?
To fix CVE-2025-25270, update the Phoenixcontact Charx Sec-3000, Sec-3050, Sec-3100, or Sec-3150 firmware to versions greater than 1.7.3.
What types of devices are affected by CVE-2025-25270?
CVE-2025-25270 affects Phoenixcontact Charx Sec-3000, Sec-3050, Sec-3100, and Sec-3150 firmware versions up to and including 1.7.3.
Can CVE-2025-25270 be exploited without authentication?
Yes, CVE-2025-25270 can be exploited by unauthenticated remote attackers, allowing them to alter device configurations.
What potential risks does CVE-2025-25270 pose?
CVE-2025-25270 poses significant risks, including unauthorized access, loss of control over device configurations, and the possibility of remote code execution.