CVE-2025-41692: Weak/Predictable root Password
A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41692?
CVE-2025-41692 has a high severity due to the potential for a remote attacker with admin privileges to brute-force critical passwords.
How do I fix CVE-2025-41692?
To fix CVE-2025-41692, update the affected Phoenixcontact Fl Switch firmware to version 3.50 or later which addresses the weak password generation issue.
Which versions are affected by CVE-2025-41692?
CVE-2025-41692 affects multiple Phoenixcontact Fl Switch models with firmware versions prior to 3.50.
What are the risks associated with CVE-2025-41692?
The risks associated with CVE-2025-41692 include unauthorized access to critical system controls and potential data breaches.
Who can exploit CVE-2025-41692?
CVE-2025-41692 can be exploited by remote attackers with admin privileges to brute-force passwords of the underlying OS.