CVE-2025-41697
An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.24%
- CWE
- CWE-1299
- Published
- 2025-12-09
- Last modified
- 2026-03-12
Affected products
- Phoenix Contact FL SWITCH 2005
- Phoenix Contact FL SWITCH 2008
- Phoenix Contact FL SWITCH 2016
- Phoenix Contact FL SWITCH 2105
- Phoenix Contact FL SWITCH 2108
- Phoenix Contact FL SWITCH 2116
- Phoenix Contact FL SWITCH 2204-2TC-2SFX
- Phoenix Contact FL SWITCH 2205
Weakness type
Related vulnerabilities
- CVE-2025-35998 — Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist...
- CVE-2025-1073 — Panasonic IR Control Hub (IR Blaster) versions 1.17 and earlier may allow an attacker with physical...
- CVE-2025-26409 — Access to Bootloader and Shell Over Serial Interface
- CVE-2024-47944 — Missing Protection Mechanism for Alternate Hardware Interface
- CVE-2024-39723 — IBM FlashSystem denial of service
- CVE-2023-29063 — Lack of DMA Access Protections
- CVE-2023-29060 — Lack of USB Whitelisting
- CVE-2022-43557 — BD BodyGuard™ Pumps – RS-232 Interface Vulnerability