CVE-2025-41692
published 2025-12-09CVE-2025-41692: A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak…
PriorityP337medium6.8CVSS 3.1
AVNACLPRHUINSCCHINAN
EPSS
0.26%
17.4th percentile
A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm.
Affected
138 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenix_contact | fl_nat_2008 | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_nat_2208 | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_nat_2304-2gc-2sfp | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2005 | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2008 | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2008f | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2016 | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2105 | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2108 | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2116 | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2204-2tc-2sfx | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2205 | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2206-2fx | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2206-2fx_sm | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2206-2fx_sm_st | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2206-2fx_st | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2206-2sfx | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2206-2sfx_pn | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2206c-2fx | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2207-fx | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2207-fx_sm | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2208 | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2208_pn | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2208c | >= 0.0.0 < 3.50 | 3.50 |
| phoenix_contact | fl_switch_2212-2tc-2sfx | >= 0.0.0 < 3.50 | 3.50 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5q5j-x9p3-cg4x: A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a we
ghsa_unreviewed·2025-12-09
CVE-2025-41692 [MEDIUM] CWE-916 GHSA-5q5j-x9p3-cg4x: A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a we
A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm.
GHSA
GHSA-chp3-94cp-3c98: An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain re
ghsa_unreviewed·2025-12-09·CVSS 6.8
CVE-2025-41696 [MEDIUM] CWE-798 GHSA-chp3-94cp-3c98: An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain re
An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device.
GHSA
GHSA-ccrq-w269-c7pj: An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e
ghsa_unreviewed·2025-12-09·CVSS 6.8
CVE-2025-41697 [MEDIUM] CWE-1299 GHSA-ccrq-w269-c7pj: An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e
An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-12-09
Published