A buffer overflow in the PROFINET service of Phoenix Contact industrial controllers lets an unauthenticated remote attacker reboot the device or execute arbitrary code, with no privileges or user interaction required.
What Is It
CVE-2025-41769 is a classic buffer overflow (CWE-120) in the PROFINET service running on a range of Phoenix Contact controllers and industrial PCs. Per the vendor advisory published through CERT@VDE, the flaw is present in the default configuration: no unusual hardening state or non-standard setup is needed to be exposed. An unauthenticated remote attacker can exploit it to reboot the device or execute arbitrary code.
The CNA (CERT@VDE) scores the issue CVSS 3.1 9.8 CRITICAL (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVSS 4.0 9.3 CRITICAL. The NVD record is still in "Received" status, so NVD has not published its own analysis or independent score; the values above are the CNA's as carried in the record.
Why It Matters
The CVSS vector describes a network attack vector with low attack complexity, requiring no privileges and no user interaction, and rates confidentiality, integrity, and availability impact as high. The affected products are PLCs, safety controllers, and edge/industrial PCs; devices where "reboot the device" is not a nuisance but a process interruption, and "execute arbitrary code" means attacker control of the control layer itself.
The vendor states the vulnerable service is present in the default configuration, which suggests that in many deployments the practical question is whether the PROFINET service is reachable from an attacker-controlled segment, not whether an operator misconfigured something. The supplied material does not describe per-product default network exposure or which interfaces the service binds to, so operators should verify reachability on their own installations rather than infer it from the advisory.
The record was published 2026-08-12. There is no CISA KEV entry in the supplied source material, so no confirmed active exploitation is documented here.
What's Vulnerable
Phoenix Contact products with firmware from 2019.0.4 up to (but not including) 2026.0.3:
- AXC F 1152, AXC F 1252, AXC F 2152, AXC F 3152
- RFC 4072R, RFC 4072S
- BPC 9102S, BPC 9202S
- EPC 1502, EPC 1522
- VL3 UPC 2440 EDGE
- VPLCNEXT CONTROL 500, 1000, 2000, 3000
Versions outside that range are listed as unaffected.
Patch Status
The version data indicates the issue is resolved in 2026.0.3 and later. Operators of any listed product should update to 2026.0.3 or newer. No other remediation, workaround, or required-action guidance is present in the supplied source material; consult the CERT@VDE CSAF advisory below for vendor-specific mitigation.
Sources
- NVD, CVE-2025-41769: https://nvd.nist.gov/vuln/detail/CVE-2025-41769
- CERT@VDE / Phoenix Contact CSAF advisory VDE-2025-056: https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json