9.8
CVE-2025-25270
- EPSS 0.21%
- Veröffentlicht 08.07.2025 07:00:58
- Zuletzt bearbeitet 11.07.2025 14:37:08
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phoenixcontact ≫ Charx Sec-3000 Firmware Version < 1.7.3
Phoenixcontact ≫ Charx Sec-3050 Firmware Version < 1.7.3
Phoenixcontact ≫ Charx Sec-3100 Firmware Version < 1.7.3
Phoenixcontact ≫ Charx Sec-3150 Firmware Version < 1.7.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.43 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-913 Improper Control of Dynamically-Managed Code Resources
The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.