# CVE-2025-41666

## Summary

- **CVE ID:** CVE-2025-41666
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-59
- **Published:** Jul 8, 2025
- **Last Modified:** Mar 12, 2026

## Description

A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file on the device after the watchdog has been initialized.

## Affected Products

- PHOENIX CONTACT — AXC F 1152 (0)
- PHOENIX CONTACT — AXC F 2152 (0)
- PHOENIX CONTACT — AXC F 3152 (0)
- PHOENIX CONTACT — BPC 9102S (0)
- PHOENIX CONTACT — RFC 4072S (0)

## References

- [CNA](https://certvde.com/en/advisories/VDE-2025-054)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.51%
- **EPSS Percentile:** 41.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._