ZeroHour

CVE-2025-41697

CVSS 3.1
6.8 medium
EPSS
<1%p14
Published
()
Modified
Description

An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692.

Vendors
phoenixcontact
Products
fl switch 2708 pn firmware, fl switch 2708 firmware, fl switch 2608 pn firmware, fl switch 2608 firmware, fl switch 2516 pn firmware, fl switch 2516 firmware, fl switch 2514-2sfp pn firmware, fl switch 2514-2sfp firmware, fl switch 2512-2gc-2sfp firmware, fl switch 2508 pn firmware, fl switch 2508\/k1 firmware, fl switch 2508 firmware
Weakness
CWE-1299
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.