ZeroHour

CVE-2025-41696

CVSS 3.1
4.6 medium
EPSS
<1%p11
Published
()
Modified
Description

An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device.

Vendors
phoenixcontact
Products
fl switch 2708 pn firmware, fl switch 2708 firmware, fl switch 2608 pn firmware, fl switch 2608 firmware, fl switch 2516 pn firmware, fl switch 2516 firmware, fl switch 2514-2sfp pn firmware, fl switch 2514-2sfp firmware, fl switch 2512-2gc-2sfp firmware, fl switch 2508 pn firmware, fl switch 2508\/k1 firmware, fl switch 2508 firmware
Weakness
CWE-798
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.