CVE-2025-41670
Published: May 27, 2026
Modified: May 27, 2026
CVSS v3.1
7.8
Description
A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the filesystem. The affected service processes data from locations that are not sufficiently protected against modification by low-privileged users. As the service runs with elevated privileges, successful exploitation may result in a local privilege escalation.
| Vendor | Product | Versions |
|---|---|---|
Phoenix Contact | AXC F 1152 | affected 0.0.0 - < 2026.0.3 |
Phoenix Contact | AXC F 1252 | affected 0.0.0 - < 2026.0.3 |
Phoenix Contact | AXC F 2000 EA | affected 0.0.0 - < 2026.0.3 |
Phoenix Contact | AXC F 2152 | affected 0.0.0 - < 2026.0.3 |
Phoenix Contact | AXC F 3152 | affected 0.0.0 - < 2026.0.3 |
Phoenix Contact | BPC 9102S | affected 0.0.0 - < 2026.0.3 |
Phoenix Contact | EPC 1522 | affected 0.0.0 - < 2026.0.3 |
Phoenix Contact | RFC 4072R | affected 0.0.0 - < 2026.0.3 |
Phoenix Contact | RFC 4072S | affected 0.0.0 - < 2026.0.3 |
Phoenix Contact | VL3 UPC 2440 EDGE | affected 0.0.0 - < 2026.0.3 |
Phoenix Contact | VPLCNEXT CONTROL 1000 | affected 0.0.0 - < 2026.0.3 |
Phoenix Contact | VPLCNEXT CONTROL 2000 | affected 0.0.0 - < 2026.0.3 |
Phoenix Contact | VPLCNEXT CONTROL 3000 | affected 0.0.0 - < 2026.0.3 |
Phoenix Contact | VPLCNEXT CONTROL 500 | affected 0.0.0 - < 2026.0.3 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now