Known Vulnerabilities for products from Phoenixcontact

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Phoenixcontact".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Phoenixcontact can be found at device.report : Phoenixcontact

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2025-41752 json An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user to c... Not Provided 2025-12-09 2026-09-30
CVE-2025-41751 json An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated user to ... Not Provided 2025-12-09 2026-09-30
CVE-2025-41750 json An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to c... Not Provided 2025-12-09 2026-09-30
CVE-2025-41749 json An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user to cli... Not Provided 2025-12-09 2026-09-30
CVE-2025-41748 json An XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to ... Not Provided 2025-12-09 2026-09-30
CVE-2025-41747 json An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user ... Not Provided 2025-12-09 2026-09-30
CVE-2025-41746 json An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user t... Not Provided 2025-12-09 2026-09-30
CVE-2025-41745 json An XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated user to... Not Provided 2025-12-09 2026-09-30
CVE-2025-41697 json An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials ob... Not Provided 2025-12-09 2026-09-30
CVE-2025-41696 json An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from ... Not Provided 2025-12-09 2026-09-30
CVE-2025-41695 json An XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick an authenticated user to send... Not Provided 2025-12-09 2026-09-30
CVE-2025-41694 json A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block... Not Provided 2025-12-09 2026-09-30
CVE-2025-41693 json A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and... Not Provided 2025-12-09 2026-09-30
CVE-2025-41692 json A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the ... Not Provided 2025-12-09 2026-09-30
CVE-2024-43384 json A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage ... Not Provided 2026-05-07 2026-05-11
CVE-2023-37864 json In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may... 7.2 - HIGH 2023-08-09 2023-08-15
CVE-2023-37863 json In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may... 7.2 - HIGH 2023-08-09 2023-08-15
CVE-2023-37862 json In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access uploa... 8.2 - HIGH 2023-08-09 2023-08-15
CVE-2023-37861 json In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code w... 8.8 - HIGH 2023-08-09 2023-08-15
CVE-2023-37860 json In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/... 7.5 - HIGH 2023-08-09 2023-08-25

Known software with vulnerabilities from Phoenixcontact

Type Vendor Product Version
HardwarePhoenixcontactAxl F Bk Eth-
Operating
System
PhoenixcontactAxl F Bk Eth Firmware-
HardwarePhoenixcontactAxl F Bk Eth Xc-
Operating
System
PhoenixcontactAxl F Bk Eth Xc Firmware-
HardwarePhoenixcontactAxl F Bk Pn-
Operating
System
PhoenixcontactAxl F Bk Pn Firmware-
ApplicationPhoenixcontactConfig-
ApplicationPhoenixcontactPc Worx-
ApplicationPhoenixcontactPc Worx Express-
ApplicationPhoenixcontactPc Worx Srt-
ApplicationPhoenixcontactPlcnext Engineer-
HardwarePhoenixcontactTc Cloud Client 1002-4g-
Operating
System
PhoenixcontactTc Cloud Client 1002-4g Firmware2.03.17
HardwarePhoenixcontactTc Cloud Client 1002-txtx-
Operating
System
PhoenixcontactTc Cloud Client 1002-txtx Firmware1.03.17
HardwarePhoenixcontactTc Router 2002t-3g-
Operating
System
PhoenixcontactTc Router 2002t-3g Firmware2.05.3
HardwarePhoenixcontactTc Router 3002t-4g-
HardwarePhoenixcontactTc Router 3002t-4g Att-
Operating
System
PhoenixcontactTc Router 3002t-4g Att Firmware2.05.3

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report