CVE-2025-41751: Reflected XSS vulnerability in pxc_portCntr.php
An XSS vulnerability in pxcportCntr.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41751?
CVE-2025-41751 is classified as a medium severity Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2025-41751?
To fix CVE-2025-41751, ensure to sanitize and validate all user inputs to prevent malicious scripts from executing.
Who is affected by CVE-2025-41751?
Devices running vulnerable versions of Phoenix Contact firmware including FL NAT 2008, FL NAT 2208, and FL Switch models are affected.
What can an attacker achieve with CVE-2025-41751?
An attacker can exploit CVE-2025-41751 to execute arbitrary scripts in the context of another user's session.
How can I identify if I am using vulnerable versions related to CVE-2025-41751?
Check your Phoenix Contact device firmware version against the affected versions listed in the CVE-2025-41751 documentation.