CVE-2025-41696: Hardcoded User Password
An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41696?
CVE-2025-41696 is considered a high severity vulnerability because it allows attackers to gain unauthorized read access to filesystem parts using hardcoded credentials.
How do I fix CVE-2025-41696?
To mitigate CVE-2025-41696, it's essential to update the affected Phoenix Contact firmware to a version that is 3.50 or higher.
What are the potential impacts of CVE-2025-41696?
Exploitation of CVE-2025-41696 can lead to unauthorized access to sensitive information stored in the device's filesystem.
Which Phoenix Contact devices are affected by CVE-2025-41696?
CVE-2025-41696 affects multiple Phoenix Contact Fl Switch devices running firmware versions lower than 3.50.
Is there a way to detect exploitation attempts for CVE-2025-41696?
Monitoring the UART port activity for unusual access patterns may indicate exploitation attempts of CVE-2025-41696.