← Vulnerability feed

Vulnerability record · CVE-2025-25269 · published 8 July 2025

CVE-2025-25269: Phoenixcontact charx sec-3000 firmware os command injection vulnerability

Phoenixcontact · Charx Sec 3000 Firmware

An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.

8.4 CVSS 3.1 High EPSS 0.25% · top 84.8% CWE-78 · OS command injection
8.4CVSS 3.1 base score
0.25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://certvde.com/de/advisories/VDE-2025-019 Third Party Advisory

Track CVE-2025-25269 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-25270Phoenixcontact charx sec-3000 firmware improper control of dynamically-managed code vulnerabilityAn unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.EPSS 0.65%9.8CVE-2024-6788Phoenixcontact charx sec-3000 firmware vulnerabilityA remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, lo…EPSS 0.50%9.8CVE-2024-26001Phoenixcontact charx sec-3000 firmware out-of-bounds write vulnerabilityAn unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not a…EPSS 0.87%9.8CVE-2024-25995Phoenixcontact charx sec-3000 firmware improper input validation vulnerabilityAn unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper i…EPSS 1.4%9.8CVE-2024-25996Phoenixcontact charx sec-3000 firmware origin validation error vulnerabilityAn unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.EPSS 0.39%8.8CVE-2025-25271Phoenixcontact charx sec-3000 firmware insecure default initialization vulnerabilityAn unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.EPSS 0.29%8.8CVE-2025-25268Phoenixcontact charx sec-3000 firmware missing authentication for critical function vulnerabilityAn unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due …EPSS 0.30%8.7CVE-2024-26288Phoenixcontact charx sec-3000 firmware cleartext transmission vulnerabilityAn unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affect…EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2025-25269), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.