CVE-2025-41748: Reflected XSS vulnerability in pxc_Dot1xCfg.php
An XSS vulnerability in pxcDot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41748?
CVE-2025-41748 is classified as a medium severity vulnerability due to its potential impact on confidentiality and integrity when exploited.
How do I fix CVE-2025-41748?
To fix CVE-2025-41748, upgrade the affected Phoenix Contact firmware to version 3.50 or higher.
What type of vulnerability is CVE-2025-41748?
CVE-2025-41748 is an XSS (Cross-Site Scripting) vulnerability that can be exploited by an unauthenticated remote attacker.
Who is affected by CVE-2025-41748?
CVE-2025-41748 affects various Phoenix Contact firmware versions, specifically those below 3.50.
What can an attacker do with CVE-2025-41748?
An attacker exploiting CVE-2025-41748 can trick authenticated users into changing parameters via the web-based management interface.