Where
-Infinity
0

Vendor Risk Score

See how phoenixcontact compares to other vendors in security performance

View Risk Score →

Software

phoenixcontact fl nat 2304-2gc-2sfp firmware
15
phoenixcontact fl switch 2005 firmware
15
phoenixcontact fl switch 2008 firmware
15
phoenixcontact fl switch 2008f
15
phoenixcontact fl switch 2016 firmware
15
phoenixcontact fl switch 2105 firmware
15
phoenixcontact fl switch 2108 firmware
15
phoenixcontact fl switch 2116 firmware
15
phoenixcontact fl switch 2204-2tc-2sfx
15
phoenixcontact fl switch 2204-2tc-2sfx firmware
15
phoenixcontact fl switch 2205 firmware
15
phoenixcontact fl switch 2206-2fx
15
phoenixcontact fl switch 2206-2fx sm firmware
15
phoenixcontact fl switch 2206-2fx sm st
15
phoenixcontact fl switch 2206-2sfx firmware
15
phoenixcontact fl switch 2206c-2fx
15
phoenixcontact fl switch 2206c-2fx firmware
15
phoenixcontact fl switch 2207-fx sm firmware
15
phoenixcontact fl switch 2208 pn
15
phoenixcontact fl switch 2212-2tc-2sfx firmware
15
phoenixcontact fl switch 2214-2fx
15
phoenixcontact fl switch 2214-2fx firmware
15
phoenixcontact fl switch 2214-2fx sm
15
phoenixcontact fl switch 2214-2sfx
15
phoenixcontact fl switch 2214-2sfx firmware
15
phoenixcontact fl nat 2008
14
phoenixcontact fl nat 2008 firmware
14
phoenixcontact fl nat 2208
14
phoenixcontact fl nat 2208 firmware
14
phoenixcontact fl nat 2304-2gc-2sfp
14
phoenixcontact fl switch 2005
14
phoenixcontact fl switch 2008
14
phoenixcontact fl switch 2008f firmware
14
phoenixcontact fl switch 2016
14
phoenixcontact fl switch 2105
14
phoenixcontact fl switch 2108
14
phoenixcontact fl switch 2116
14
phoenixcontact fl switch 2205
14
phoenixcontact fl switch 2206-2fx firmware
14
phoenixcontact fl switch 2206-2fx sm
14
phoenixcontact fl switch 2206-2fx sm st firmware
14
phoenixcontact fl switch 2206-2fx st
14
phoenixcontact fl switch 2206-2fx st firmware
14
phoenixcontact fl switch 2206-2sfx
14
phoenixcontact fl switch 2206-2sfx pn
14
phoenixcontact fl switch 2206-2sfx pn firmware
14
phoenixcontact fl switch 2207-fx
14
phoenixcontact fl switch 2207-fx firmware
14
phoenixcontact fl switch 2207-fx sm
14
phoenixcontact fl switch 2208
14
Severity
8
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses resources which leads to a reduced performance of the management functions. Switching functionality is not affected.

First published (updated )
Severity
4.6
AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device.

First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block until it receives more data, resulting in a DoS condition of the websserver.

First published (updated )
Severity
6.8
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm.

First published (updated )
Severity
6.8
AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

An XSS vulnerability in dynconn.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

An XSS vulnerability in pxcportCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

An XSS vulnerability in pxcportSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

An XSS vulnerability in pxcvlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

An XSS vulnerability in pxcDot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

An XSS vulnerability in portutil.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

An XSS vulnerability in pxcPortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

An XSS vulnerability in pxcportCntr.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

An XSS vulnerability in pxcportSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

First published (updated )
Severity
8.8
AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.

First published (updated )
Severity
8.4
OS Command Injection
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.

First published (updated )
Severity
8.8
AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root.

First published (updated )
Severity
7.8
Input Validation
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation.

First published (updated )
Severity
5.2
AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the stations until they got restarted by the watchdog.

First published (updated )
Severity
8.2
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only EichrechtAgents and potential denial-of-service for these stations.

First published (updated )
Severity
5.3
Input Validation
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restarted by the watchdog.

First published (updated )
Severity
8.1
Code Injection
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FWINCOMING.FROMIP FWINCOMING.INIP FWOUTGOING.FROMIP FWOUTGOING.INIP FWRULESETS.FROMIP FWRULESETS.INIP environment variable which can lead to a DoS.

First published (updated )
Severity
8.1
Code Injection
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FWINCOMING.FROMIP FWINCOMING.INIP FWOUTGOING.FROMIP FWOUTGOING.INIP environment variable which can lead to a DoS.

First published (updated )
Severity
8.1
Code Injection
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FWPORTFORWARDING.SRCIP environment variable which can lead to a DoS.

First published (updated )
Severity
8.1
Code Injection
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FWNAT.INIP environment variable which can lead to a DoS.

First published (updated )
Severity
8.1
Code Injection
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

A low privileged remote attacker can perform configuration changes of the ospf service through OSPFINTERFACE.SIMPLEKEY, OSPFINTERFACE.DIGESTKEY environment variables which can lead to a DoS.

First published (updated )
Severity
8.8
Code Injection, Input Validation
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203