ZeroHour

CVE-2025-41692

CVSS 3.1
6.8 medium
EPSS
<1%p22
Published
()
Modified
Description

A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm.

Vendors
phoenixcontact
Products
fl switch 2708 pn firmware, fl switch 2708 firmware, fl switch 2608 pn firmware, fl switch 2608 firmware, fl switch 2516 pn firmware, fl switch 2208c firmware, fl switch 2208 pn firmware, fl switch 2208 firmware, fl switch 2207-fx sm firmware, fl switch 2207-fx firmware, fl switch 2206c-2fx firmware, fl switch 2206-2sfx pn firmware
Weakness
CWE-916
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.