CVE-2025-41694

Severity
6.5MEDIUM
EPSS
0.2%
top 58.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9

Description

A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block until it receives more data, resulting in a DoS condition of the websserver.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages138 packages

CVEListV5phoenix_contact/fl_nat_20080.0.03.50
CVEListV5phoenix_contact/fl_nat_22080.0.03.50
CVEListV5phoenix_contact/fl_switch_20050.0.03.50
CVEListV5phoenix_contact/fl_switch_20080.0.03.50
CVEListV5phoenix_contact/fl_switch_20160.0.03.50

🔴Vulnerability Details

2
CVEList
Authenticated Denial-of-Service via Webshell2025-12-09
GHSA
GHSA-56w8-9x5w-fmh9: A low privileged remote attacker can run the webshell with an empty command containing whitespace2025-12-09
CVE-2025-41694 (MEDIUM CVSS 6.5) | A low privileged remote attacker ca | cvebase.io