www.nozominetworks.com
Privilege Escalation Vulnerabilities in Phoenix PLCnext Controllers Disclosed
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Nozomi Networks Labs identified a privilege escalation vulnerability chain in the Phoenix PLCnext AXC F 3152 industrial controller, allowing low-privileged users to gain root access. The vulnerabilities stem from weaknesses in privilege management within the web interface, enabling unauthorized actions. This affects multiple PLCnext models, posing risks to critical infrastructure like water treatment and energy management systems. The most severe flaw allows users with an Engineer profile to escalate privileges and fully compromise the system. Following responsible disclosure, Phoenix released updated firmware to address these issues. The vulnerabilities were published as CVE-2025-41669 on May 27, 2026.
Key Points: • Privilege escalation vulnerabilities in Phoenix PLCnext AXC F 3152 allow unauthorized access. • Affected systems include critical infrastructure like water treatment and energy management. • Phoenix released firmware updates to mitigate the identified vulnerabilities.