Skip to main content

Vendor archive

phoenixcontact CVEs

Beta · best-effort

154 CVEs tagged to vendor phoenixcontact18 Critical, 98 High, 37 Medium, 1 Low, 0 Unrated.

CVE-2025-25271

Published Jul 8, 2025

An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-25270

Published Jul 8, 2025

An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-25269

Published Jul 8, 2025

An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-25268

Published Jul 8, 2025

An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-24006

Published Jul 8, 2025

A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-24005

Published Jul 8, 2025

A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-24004

Published Jul 8, 2025

A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a t…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-24003

Published Jul 8, 2025

An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integri…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-24002

Published Jul 8, 2025

An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 154 CVEsPage 1 of 7