CVE-2025-41769
Received Received - Intake

PROFINET Service Buffer Overflow in Industrial Device

Vulnerability report for CVE-2025-41769, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: CERT VDE

Description

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-12
AI Q&A
2026-08-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
phoenix_contact plcnext_firmware to 2026.0.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a buffer overflow flaw in the PROFINET service of Phoenix Contact PLCnext firmware. An unauthenticated remote attacker can exploit it to reboot the device or execute arbitrary code by sending specially crafted network traffic.

Detection Guidance

Detecting this vulnerability requires checking if your PLCnext firmware version is prior to 2026.0.3. Use the device's web interface or CLI to verify the firmware version. Network scanning tools like Nmap can identify affected devices by checking for PROFINET services on Phoenix Contact hardware.

Impact Analysis

It can cause denial-of-service, unexpected system behavior, or unauthorized code execution. This may lead to system downtime, data breaches, or full device compromise. Affected devices include multiple PLCnext Control models like Catan C1 and EPC series.

Mitigation Strategies

Immediately update all affected PLCnext firmware to version 2026.0.3 or later. Isolate affected devices in closed networks or behind firewalls to limit exposure. Disable unnecessary PROFINET services if not required for operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-41769. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart