Vulnerability intelligence
CVE-2025-41770
An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.
CVSS Score
8.7
High
EPSS — Exploit Probability
0.5%
Riskier than 44% of all CVEs · checked 2026-09-27
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Aug 14, 2026 · latest Aug 14, 2026
Coverage timeline
-
Critical RCE flaw in Phoenix Contact PLCnext firmware, patch urgedsecurityonline.info · Aug 14, 2026