CVE-2025-41697: Shell access to UART Console
An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41697?
CVE-2025-41697 has a critical severity rating as it allows an attacker to gain root access via an undocumented UART port.
How do I fix CVE-2025-41697?
To fix CVE-2025-41697, update the firmware of the affected Phoenix Contact Fl Switch models to at least version 3.50.
What devices are affected by CVE-2025-41697?
CVE-2025-41697 affects various models of Phoenixcontact Fl Switch including 2708, 2608, 2516, and others running firmware versions prior to 3.50.
Can CVE-2025-41697 be exploited remotely?
CVE-2025-41697 requires physical access to the device through the undocumented UART port to exploit the vulnerability.
Is CVE-2025-41697 linked to other vulnerabilities?
Yes, CVE-2025-41697 is linked to CVE-2025-41692 as it utilizes credentials that could be obtained through that vulnerability.