CVE-2025-41752: Reflected XSS vulnerability in pxc_portSfp.php
An XSS vulnerability in pxcportSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41752?
CVE-2025-41752 has been classified as a medium severity XSS vulnerability that could allow an attacker to manipulate web-based management parameters.
How do I fix CVE-2025-41752?
To mitigate CVE-2025-41752, users should update the affected firmware to version 3.50 or later as recommended by the vendor.
What types of devices are affected by CVE-2025-41752?
CVE-2025-41752 affects various Phoenix Contact devices including the FL Switch and FL NAT firmware versions prior to 3.50.
Who can exploit CVE-2025-41752?
CVE-2025-41752 can be exploited by unauthenticated remote attackers who can trick authenticated users into clicking a malicious link.
What are the potential impacts of CVE-2025-41752?
The exploitation of CVE-2025-41752 may lead to unauthorized modifications to device settings in the web-based management interface.