CVE-2025-41749: Reflected XSS vulnerability in port_util.php
An XSS vulnerability in portutil.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41749?
CVE-2025-41749 has a high severity rating due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2025-41749?
To mitigate CVE-2025-41749, upgrade the affected Phoenix Contact firmware to a version that is 3.50 or higher.
Who is affected by CVE-2025-41749?
CVE-2025-41749 affects users of Phoenix Contact Fl switches with firmware versions lower than 3.50.
What type of attack is CVE-2025-41749 associated with?
CVE-2025-41749 is associated with cross-site scripting (XSS) attacks that can be executed by unauthenticated remote attackers.
Can CVE-2025-41749 be exploited remotely?
Yes, CVE-2025-41749 can be exploited remotely, allowing attackers to manipulate web-based management settings.