<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_phoenixcontactgmbhcokg/10</id>
  <title>Most recent entries from csaf_phoenixcontactgmbhcokg</title>
  <updated>2026-10-02T11:22:39.222844+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-027</id>
    <title>VDE-2026-027 — Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices</title>
    <updated>2026-09-16T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and modified schemata can be used to read sensitive information such as password hashes or private keys from the devices.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-027"/>
    <published>2026-09-16T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-056</id>
    <title>vde-2025-056 — Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware</title>
    <updated>2026-08-12T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-056"/>
    <published>2026-08-12T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-008</id>
    <title>VDE-2026-008 — Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers</title>
    <updated>2026-07-30T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-008"/>
    <published>2026-07-30T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-060</id>
    <title>VDE-2026-060 — Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers</title>
    <updated>2026-06-03T10:01:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>VDE-2026-060: A unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers has been discovered.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-060"/>
    <published>2026-06-03T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-050</id>
    <title>VDE-2026-050 — Phoenix Contact: PLCnext Firmware Security Issues Related to APPs and Configuration Files</title>
    <updated>2026-05-27T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>This advisory addresses security issues in PLCnext firmware versions prior to 2026.0.3 that are related to APP handling and the processing of configuration files. The identified vulnerabilities affect APP installation authenticity as well as the handling of configuration data in writable directories. Successful exploitation may allow authenticated attackers with different privilege levels to compromise integrity, availability, and system security of affected PLCnext Control. Both issues are resolved starting with PLCnext firmware version 2026.0.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-050"/>
    <published>2026-05-27T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-023</id>
    <title>VDE-2026-023 — Phoenix Contact: Several products are affected by vulnerabilities found in OpenSSL</title>
    <updated>2026-04-22T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Attacks are possible when installing key files and digitally signed objects. These attacks can only be carried out if these files are uploaded and installed by a logged-in user with high privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-023"/>
    <published>2026-04-22T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-104</id>
    <title>VDE-2025-104 — Phoenix Contact: Multiple Vulnerabilities in FL SWITCH 2xxx, FL SWITCH TSN 23xx and FL SWITCH 59xx Firmware</title>
    <updated>2026-03-18T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities have been identified in the FL SWITCH 2xxx, FL SWITCH TSN 23xx and FL SWITCH 59xx firmware prior to version 3.53. One of these (CVE-2026-22317) enables an attacker to execute system commands as root user on the device. Five other vulnerabilities (CVE-2026-22316, CVE-2026-22318, CVE-2026-22319, CVE-2026-22320 and CVE-2026-22321) are related to Denial of Service (DoS) attacks, which partly limit the device's functionality. Another vulnerability (CVE-2026-22322) relates to reflected cross-site scripting in the web-based management of the device. And one vulnerability (CVE-2026-22323) relates to Cross‑Site Request Forgery in the web-based management of the device. All vulnerabilities have been resolved in firmware version 3.53.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-104"/>
    <published>2026-03-18T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-109</id>
    <title>VDE-2025-109 — Phoenix Contact: Unbounded growth of the session cache in TCP encapsulation service in FL MGUARD 2xxx and 4xxx firmware</title>
    <updated>2026-02-23T14:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The OpenSSL library used in the affected products is vulnerable to an unbounded growth of the session cache in the TLSv1.3 implementation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-109"/>
    <published>2026-02-10T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-073</id>
    <title>VDE-2025-073 — Phoenix Contact: Security Advisory for TC ROUTER and CLOUD CLIENT Industrial mobile network routers</title>
    <updated>2026-01-13T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A code injection vulnerability at the upload-config endpoint in the firmware of TC ROUTER and CLOUD CLIENT Industrial Mobile network routers has been discovered that can be exploited by an high privileged attacker.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-073"/>
    <published>2026-01-13T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-071</id>
    <title>VDE-2025-071 — Phoenix Contact: Multiple Vulnerabilities in FL SWITCH 2xxx Firmware</title>
    <updated>2026-01-12T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities have been identified in the FL SWITCH 2xxx firmware prior to version 3.50. Two of these (CVE-2025-41692 and CVE-2025-41696) enable an attacker to access the device's file system. Two other vulnerabilities (CVE-2025-41693 and CVE-2025-41694) are related to Denial of Service (DoS) attacks, which partly limit the device's functionality. Another vulnerability (CVE-2025-41697) allows an unauthenticated physical attacker to access a login shell via an undocumented UART port. Furthermore, there are multiple vulnerabilities relating to reflected cross-site scripting in the web-based management of the device. All vulnerabilities have been resolved in firmware version 3.50.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-071"/>
    <published>2025-12-09T08:00:00+00:00</published>
  </entry>
</feed>
