Buffer Overflow Vulnerability in PROFINET Service of Phoenix Contact Devices
CVE-2025-41769

9.3CRITICAL

Key Information:

Vendor
CVE Published:
12 August 2026

What is CVE-2025-41769?

A buffer overflow vulnerability exists in the default configuration of the PROFINET service on Phoenix Contact devices. This vulnerability can be exploited by unauthenticated remote attackers, potentially allowing them to reboot the device or execute arbitrary code, posing significant security risks.

Affected Version(s)

AXC F 1152 2019.0.4 < 2026.0.3

AXC F 1252 2019.0.4 < 2026.0.3

AXC F 2152 2019.0.4 < 2026.0.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CyberDanube
.