CVE-2025-41694
—CVSS 3.1
6.5 medium
EPSS
<1%p40
Published
()
Modified
Description
A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block until it receives more data, resulting in a DoS condition of the websserver.
- Vendors
- phoenixcontact
- Products
- fl switch 2708 pn firmware, fl switch 2708 firmware, fl switch 2608 pn firmware, fl switch 2608 firmware, fl switch 2516 pn firmware, fl switch 2208c firmware, fl switch 2208 pn firmware, fl switch 2208 firmware, fl switch 2207-fx sm firmware, fl switch 2207-fx firmware, fl switch 2206c-2fx firmware, fl switch 2206-2sfx pn firmware
- Weakness
- CWE-770
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.