CVE-2025-41667 Details
Description
A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to any file on the device.
A vulnerability exists in Phoenix Contact PLCnext firmware versions prior to 2025.0.2, allowing low-privileged remote attackers with file access to manipulate a critical file used by the arp-preinit script. This manipulation could lead to unauthorized read, write, and execute access to any file on the device.
Users are advised to update to the latest firmware version 2025.0.2. Phoenix Contact recommends always using an up-to-date version of PLCnext Engineer.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 8, 2025CISA-ADP
Assessed Jul 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://certvde.com/en/advisories/VDE-2025-054 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Phoenix Contact AXC F 1152 | < 2025.0.2 (semver) |
CPE
Remediation
| |
| Phoenix Contact AXC F 2152 | < 2025.0.2 (semver) |
CPE
Remediation
| |
| Phoenix Contact AXC F 3152 | < 2025.0.2 (semver) |
CPE
Remediation
| |
| Phoenix Contact BPC 9102S | < 2025.0.2 (semver) |
CPE
Remediation
| |
| Phoenix Contact RFC 4072S | < 2025.0.2 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2025 | New CVE Received | [email protected] |
Volerion