SYS::ONLINE
Wasteland.
Briefs1888
Issues23
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2025-41769 2026-08-12

Phoenix Contact PLCnext Devices: Critical Unauthenticated PROFINET Buffer Overflow (CVE-2025-41769)

"A buffer overflow in the PROFINET service of Phoenix Contact industrial controllers lets an unauthenticated remote attacker reboot the device or execute arbitrary code, with no privileges or user interaction required."

A buffer overflow in the PROFINET service of Phoenix Contact industrial controllers lets an unauthenticated remote attacker reboot the device or execute arbitrary code, with no privileges or user interaction required.

What Is It

CVE-2025-41769 is a classic buffer overflow (CWE-120) in the PROFINET service running on a range of Phoenix Contact controllers and industrial PCs. Per the vendor advisory published through CERT@VDE, the flaw is present in the default configuration: no unusual hardening state or non-standard setup is needed to be exposed. An unauthenticated remote attacker can exploit it to reboot the device or execute arbitrary code.

The CNA (CERT@VDE) scores the issue CVSS 3.1 9.8 CRITICAL (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVSS 4.0 9.3 CRITICAL. The NVD record is still in "Received" status, so NVD has not published its own analysis or independent score; the values above are the CNA's as carried in the record.

Why It Matters

The CVSS vector describes a network attack vector with low attack complexity, requiring no privileges and no user interaction, and rates confidentiality, integrity, and availability impact as high. The affected products are PLCs, safety controllers, and edge/industrial PCs; devices where "reboot the device" is not a nuisance but a process interruption, and "execute arbitrary code" means attacker control of the control layer itself.

The vendor states the vulnerable service is present in the default configuration, which suggests that in many deployments the practical question is whether the PROFINET service is reachable from an attacker-controlled segment, not whether an operator misconfigured something. The supplied material does not describe per-product default network exposure or which interfaces the service binds to, so operators should verify reachability on their own installations rather than infer it from the advisory.

The record was published 2026-08-12. There is no CISA KEV entry in the supplied source material, so no confirmed active exploitation is documented here.

What's Vulnerable

Phoenix Contact products with firmware from 2019.0.4 up to (but not including) 2026.0.3:

Versions outside that range are listed as unaffected.

Patch Status

The version data indicates the issue is resolved in 2026.0.3 and later. Operators of any listed product should update to 2026.0.3 or newer. No other remediation, workaround, or required-action guidance is present in the supplied source material; consult the CERT@VDE CSAF advisory below for vendor-specific mitigation.

Sources