CVE-2025-41717 Details
Description
An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code injection as root. This results in a total loss of confidentiality, availability and integrity due to improper control of code generation ('Code Injection’).
A code injection vulnerability has been identified in the firmware of Phoenix Contact TC ROUTER and CLOUD CLIENT Industrial Mobile Network Routers. This vulnerability allows an unauthenticated remote attacker to manipulate a high-privileged user into uploading a malicious payload through the config-upload endpoint. Exploitation of this vulnerability leads to code execution with root privileges, causing a complete loss of confidentiality, integrity, and availability on the affected devices.
Users are advised to upgrade to the latest firmware version. For TC ROUTER and CLOUD CLIENT products, the specific fixed versions vary by model. Consult the Phoenix Contact Security Advisory VDE-2025-073 for detailed upgrade instructions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 13, 2026CISA-ADP
Assessed Jan 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://seclists.org/fulldisclosure/2026/Feb/3 | CVE | |
| https://certvde.com/de/advisories/VDE-2025-073 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Phoenix Contact CLOUD CLIENT 1101T-TX | All versions |
CPE
Remediation
| |
| Phoenix Contact TC CLOUD CLIENT 1002-4G ATT | All versions |
CPE
Remediation
| |
| Phoenix Contact TC CLOUD CLIENT 1002-TX | All versions |
CPE
Remediation
| |
| Phoenix Contact TC ROUTER 2002T-3G | All versions |
CPE
Remediation
| |
| Phoenix Contact TC ROUTER 2002T-4G | All versions |
CPE
Remediation
| |
| Phoenix Contact TC ROUTER 3002T-3G | < FW 3.08.8 |
CPE
Remediation
| |
| Phoenix Contact TC ROUTER 3002T-4G | < FW 3.08.8 |
CPE
Remediation
| |
| Phoenix Contact TC ROUTER 3002T-4G ATT | All versions |
CPE
Remediation
| |
| Phoenix Contact TC ROUTER 3002T-4G GL | All versions |
CPE
Remediation
| |
| Phoenix Contact TC ROUTER 3002T-4G VZW | All versions |
CPE
Remediation
| |
| Phoenix Contact TC ROUTER 5004T-5G EU | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 5, 2026 | CVE Modified | CVE |
| Jan 13, 2026 | New CVE Received | [email protected] |
Volerion