Privilege Escalation Vulnerabilities in Phoenix PLCnext Controllers Disclosed

Privilege Escalation Vulnerabilities in Phoenix PLCnext Controllers Disclosed

First seen 2 Jun 2026, 18:10 UTC Industrialcyber.Cowww.nozominetworks.com 80% similarity 70.5

Article Content

Browse articles
ThreatCluster

Nozomi Networks Labs identified a privilege escalation vulnerability chain in the Phoenix PLCnext AXC F 3152 industrial controller, allowing low-privileged users to gain root access. The vulnerabilities stem from weaknesses in privilege management within the web interface, enabling unauthorized actions. This affects multiple PLCnext models, posing risks to critical infrastructure like water treatment and energy management systems. The most severe flaw allows users with an Engineer profile to escalate privileges and fully compromise the system. Following responsible disclosure, Phoenix released updated firmware to address these issues. The vulnerabilities were published as CVE-2025-41669 on May 27, 2026.

Key Points: • Privilege escalation vulnerabilities in Phoenix PLCnext AXC F 3152 allow unauthorized access. • Affected systems include critical infrastructure like water treatment and energy management. • Phoenix released firmware updates to mitigate the identified vulnerabilities.

ThreatCluster AI

Timeline

2026-05-27
CVE-2025-41669 published
Nozomi Networks Labs disclosed a privilege escalation vulnerability in Phoenix PLCnext controllers affecting multiple models.
Industrialcyber.Co
2026-06-02
Vulnerabilities disclosed
Nozomi Networks Labs detailed privilege escalation flaws allowing low-privileged users to gain root access in PLCnext controllers.
www.nozominetworks.com
Recent
Firmware updates released
Phoenix promptly addressed the reported vulnerabilities by releasing updated firmware for affected devices.
Industrialcyber.Co

Community

Browse all →