Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2657 articles · 156795 vulns · 36/41 feeds (7d)
← Back to list
8.8
CVE-2025-41669PATCHED
phoenix contact · axc f

Insufficient Verification of Data Authenticity

Description

The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.

Affected Products

VendorProductVersions
phoenix contactaxc f0.0.0, 0.0.0, 0.0.0, 0.0.0, 0.0.0, 0.0.0, 0.0.0, 0.0.0, 0.0.0, 0.0.0, 0.0.0, 0.0.0, 0.0.0, 0.0.0

References

  • https://www.certvde.com/en/advisories/VDE-2026-050/

Related News (1 articles)

Tier C
VulDB11h ago
CVE-2025-41669 | Phoenix Contact VPLCNEXT CONTROL 500 prior 2026.0.3 signature verification (VDE-2026-050)
→ No new info (linked only)
CVSS 3.18.8 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.0.3
CWECWE-347
PublishedMay 27, 2026
Last enriched10h agov2
Trending Score24
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (3)

NONECVE-2025-41670
Untrusted Search Path
Trending: 24
PRE-CVE
Multiple Firmware Security Vulnerabilities in Phoenix Contact PLCnext Products
Trending: 20
HIGHCVE-2024-43384EXP
Phoenix Contact: Improper removal of sensitive information in MGUARD products
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 27, 2026
Discovered by ZDM
May 27, 2026
Updated: description, affectedVersions, severity
May 27, 2026
Patch Available
May 27, 2026

Version History

v2
Last enriched 10h ago
v2Tier C10h ago

Updated description with new technical details, changed vendor and product, added affected versions, and updated severity to CRITICAL.

descriptionaffectedVersionsseverity
via VulDB
v112h ago

Initial creation