Phoenixcontact
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Phoenixcontact product.
RSS Feeds for Phoenixcontact security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Phoenixcontact products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Phoenixcontact Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 46 vulnerabilities in Phoenixcontact with an average score of 8.2 out of ten. Phoenixcontact did not have any published security vulnerabilities last year. That is, 46 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 46 | 8.21 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 8 | 8.56 |
| 2022 | 4 | 8.23 |
| 2021 | 2 | 7.40 |
| 2020 | 4 | 7.80 |
| 2019 | 4 | 7.80 |
It may take a day or so for new Phoenixcontact vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Phoenixcontact Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-27565 | Sep 16, 2026 |
Unauthenticated IODD File Upload in Industrial Automation SystemAn unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot. |
|
| CVE-2026-27564 | Sep 16, 2026 |
Command Injection: /api/datastorage/data (PUT) Root ExecutionA high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device. |
|
| CVE-2026-27563 | Sep 16, 2026 |
Cmd Injection in /api/datastorage/data Allows Root ExecA high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device. |
|
| CVE-2026-27562 | Sep 16, 2026 |
Command Injection in /api/iodd/config Allows Root Exec on IoT DeviceA high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device. |
|
| CVE-2026-27561 | Sep 16, 2026 |
Command Injection via /api/iodd/config Enables Root ExecutionA high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device. |
|
| CVE-2026-27560 | Sep 16, 2026 |
Command Injection in IoT Device's /api/status/data EndpointA high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device. |
|
| CVE-2026-27559 | Sep 16, 2026 |
IoT Command Injection via /api/status/data Enabling Root ExecutionA low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device. |
|
| CVE-2026-27558 | Sep 16, 2026 |
CVE-2026-27558: PHP CGI Command Injection via /index.php EndpointA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device. |
|
| CVE-2026-27557 | Sep 16, 2026 |
Path Traversal in /index.php/view_uploaded_iodd_file Exposes SSH Private KeysAn unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read. |
|
| CVE-2026-27556 | Sep 16, 2026 |
Low-Privileged Remote LFI via /index.php/ajax/save_iodd_parameters (PHP)A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device. |
|
| CVE-2026-27555 | Sep 16, 2026 |
LFI in /index.php/ajax/get_iodd_port_info allows PHP code execA low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device. |
|
| CVE-2026-27554 | Sep 16, 2026 |
Cmd Injection in /index.php/ajax/save_iodd_parameters (Root Exec)A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device. |
|
| CVE-2026-27553 | Sep 16, 2026 |
CVE-2026-27553: Remote Hash Disclosure via Schema Path Manip in Desktop CentralA low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes. |
|
| CVE-2026-27552 | Sep 16, 2026 |
Improper Authorization Allows IODD Upload on IED Web InterfaceA low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes. |
|
| CVE-2026-27551 | Sep 16, 2026 |
Command Injection in /index.php/ajax/parameterManage Allows RCE with Root PrivilegesA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device. |
|
| CVE-2026-27550 | Sep 16, 2026 |
Command Injection in Field_Shadow_Password Class Allows Root ExecA low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device. |
|
| CVE-2026-27549 | Sep 16, 2026 |
Cmd Inject in /index.php/attached_devices_tab/do_upload Enables Root Exec on IoTA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device. |
|
| CVE-2026-27548 | Sep 16, 2026 |
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentialsA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device. |
|
| CVE-2026-27547 | Sep 16, 2026 |
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentialsA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device. |
|
| CVE-2026-27546 | Sep 16, 2026 |
An unauthenticated remote attackerAn unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured. |
|
| CVE-2025-41771 | Aug 12, 2026 |
SQLi in controller web interface affects SQLite notification DBAn authenticated attacker with low privileges can access an endpoint in the controllers web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the systems notification functionality. |
And others... |
| CVE-2025-41770 | Aug 12, 2026 |
Unauth DoS via PLCnext Engineer Comm InterfaceAn unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted. |
And others... |
| CVE-2025-41769 | Aug 12, 2026 |
PROFINET Buffer Overflow: Remote RCE Enables Device RebootThe device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code. |
And others... |
| CVE-2026-7849 | Jul 30, 2026 |
Cmd Injection via Special Elements in System ConfigDue to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root. |
And others... |
| CVE-2026-44108 | Jul 30, 2026 |
Premature Firewall Shutdown Exposes ServicesDue to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise. |
And others... |
| CVE-2026-44107 | Jul 30, 2026 |
CharxModbusServer Unauth Reboot via Modbus TCP DoSA reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack. |
And others... |
| CVE-2026-44105 | Jul 30, 2026 |
Local user credentials leaked via logs enabling SSH login as user-appThe credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted. |
And others... |
| CVE-2026-44106 | Jul 30, 2026 |
Priv Esc via User-App init-scriptA privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. |
And others... |
| CVE-2026-44104 | Jul 30, 2026 |
Firmware Update in Charging Controller Lacks Signature (CVE-202644104)The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise. |
And others... |
| CVE-2026-44103 | Jul 30, 2026 |
Unauthenticated Firmware Injection via JupiCore Service (CVE-2026-44103)An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104. |
And others... |
| CVE-2026-44102 | Jul 30, 2026 |
Unauthenticated OCPP Backend Remote Firmware Download VulnerabilityAn unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process. |
And others... |
| CVE-2026-44101 | Jul 30, 2026 |
Unauthenticated reconfig of CHARX OCPP Agent leads to DoS & Data DisclosureDue to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker. |
And others... |
| CVE-2026-44100 | Jul 30, 2026 |
Unauth Remote Reconfig Attack on CHARX JupiCore Charging ServiceThe CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering. |
And others... |
| CVE-2026-44099 | Jul 30, 2026 |
Local Privilege Escalation: User to Root via System ConfigA privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. |
And others... |
| CVE-2026-44098 | Jul 30, 2026 |
OS Cmd Injection in OCPP Backend via firewallbypassThis vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted. |
And others... |
| CVE-2026-44097 | Jul 30, 2026 |
IoT REST Firmware Upload Flaw: Arbitrary File PersistenceA low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service. |
And others... |
| CVE-2026-44096 | Jul 30, 2026 |
Privilege Escalation in udhcpc, local charx-web execs as rootA privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise. |
And others... |
| CVE-2026-44095 | Jul 30, 2026 |
Priv Esc via Network Config Script on LinuxA privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. |
And others... |
| CVE-2026-44094 | Jul 30, 2026 |
Firmware Partition Default Credentials Allow Unprivileged SSH AccessAn unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted. |
And others... |
| CVE-2026-44093 | Jul 30, 2026 |
Local Priv. Escalation via init-script in systemd (CVE-2026-44093)A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. |
And others... |
| CVE-2026-44092 | Jul 30, 2026 |
Unauthenticated Input Injection in ModbusServer via MQTT (CVE-2026-44092)An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss. |
And others... |
| CVE-2026-44091 | Jul 30, 2026 |
Unauthenticated ID Injection in MQTT Broker Creates Config EntryAn unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss. |
And others... |
| CVE-2026-44090 | Jul 30, 2026 |
Unauthenticated Access to MQTT Broker (CVE-2026-44090)Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised. |
And others... |
| CVE-2026-41032 | Jun 03, 2026 |
Unauthenticated Adjacent Log File Disclosure in ControllerIt is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information. |
And others... |
| CVE-2025-41669 | May 27, 2026 |
PLCnext Control Arbitrary Code Execution via Unverified APP InstallThe Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control. |
And others... |
| CVE-2025-41670 | May 27, 2026 |
Privileged Service LPE via User-Writable Config (CVE-2025-41670)A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the filesystem. The affected service processes data from locations that are not sufficiently protected against modification by low-privileged users. As the service runs with elevated privileges, successful exploitation may result in a local privilege escalation. |
And others... |
| CVE-2023-5592 | Dec 14, 2023 |
Unauthenticated Remote Download w/o Integrity Check in PHOENIX MULTIPROGDownload of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity. |
|
| CVE-2023-46144 | Dec 14, 2023 |
PLCnext Integrity Check Omission Allows Remote Low-Privileged ExploitationA download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices. |
|
| CVE-2023-46143 | Dec 14, 2023 |
CVE-2023-46143: Remote PLC Mod via Missing Integrity CheckDownload of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC. |
And others... |
| CVE-2023-46142 | Dec 14, 2023 |
PLCnext PLCs: Permission Misassignment Lets Full AccessA incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices. |
|