An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.
総合評価: CVE-2025-41746 は高リスク(66.4/100)。CVSS 深刻度は高。悪用される可能性が高い(EPSS 8.24%、94 パーセンタイル) 根拠: EPSS 上、短期間での悪用可能性は高い水準です。 直近 1 日で EPSS が +8.13% 上昇。悪用への関心が高まっている可能性があります。 推奨対応: 悪用可能性が高いため、影響範囲の確認と修補の優先付けを推奨します。
リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。
EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。
| # | 日付 | 旧 EPSS スコア | 新 EPSS スコア | Δ(新 − 旧) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.11% | 8.24% | +8.13% |
| 2 | 2026-05-07 | 0.15% | 0.11% | -0.04% |
| 3 | 2026-02-15 | — | 0.15% | — |
EPSS の全履歴 (全 4 件)
この CVE の CVSS 指標。
| ベーススコア | バージョン | 深刻度 | ベクトル | 悪用しやすさ | 影響 | スコアの出典 |
|---|---|---|---|---|---|---|
| 7.1 | 3.1 | HIGH |
|
2.8 | 3.7 | [email protected] |
| ベンダー | 製品 | バージョン | 生の CPE |
|---|---|---|---|
| phoenixcontact | fl_switch_2406-2sfx_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2406-2sfx_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2408_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2408_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2408_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2408_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2412-2tc-2sfx_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2412-2tc-2sfx_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2414-2sfx_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2414-2sfx_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2414-2sfx_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2414-2sfx_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2416_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2416_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2416_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2416_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2504-2gc-2sfp_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2504-2gc-2sfp_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2506-2sfp_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2506-2sfp_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2506-2sfp\/k1_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2506-2sfp\/k1_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2506-2sfp_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2506-2sfp_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2508_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2508_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2508\/k1_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2508\/k1_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2508_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2508_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2512-2gc-2sfp_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2512-2gc-2sfp_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2514-2sfp_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2514-2sfp_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2514-2sfp_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2514-2sfp_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2516_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2516_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2516_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2516_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2608_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2608_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2608_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2608_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2708_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2708_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2708_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2708_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_nat_2008_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_nat_2008_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_nat_2208_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_nat_2208_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_nat_2304-2gc-2sfp_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_nat_2304-2gc-2sfp_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2005_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2005_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2008_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2008_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2008f_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2008f_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2016_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2016_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2105_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2105_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2108_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2108_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2116_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2116_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2204-2tc-2sfx_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2204-2tc-2sfx_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2205_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2205_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2206-2fx_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2206-2fx_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2206-2fx_sm_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2206-2fx_sm_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2206-2fx_sm_st_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2206-2fx_sm_st_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2206-2fx_st_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2206-2fx_st_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2206-2sfx_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2206-2sfx_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2206-2sfx_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2206-2sfx_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2206c-2fx_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2206c-2fx_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2207-fx_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2207-fx_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2207-fx_sm_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2207-fx_sm_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2208_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2208_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2208_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2208_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2208c_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2208c_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2212-2tc-2sfx_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2212-2tc-2sfx_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2214-2fx_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2214-2fx_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2214-2fx_sm_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2214-2fx_sm_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2214-2sfx_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2214-2sfx_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2214-2sfx_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2214-2sfx_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2216_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2216_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2216_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2216_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2303-8sp1 | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2303-8sp1:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2304-2gc-2sfp_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2304-2gc-2sfp_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2306-2sfp_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2306-2sfp_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2306-2sfp_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2306-2sfp_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2308_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2308_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2308_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2308_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2312-2gc-2sfp_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2312-2gc-2sfp_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2314-2sfp_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2314-2sfp_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2314-2sfp_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2314-2sfp_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2316_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2316_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2316\/k1_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2316\/k1_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2316_pn_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2316_pn_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2404-2tc-2sfx_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2404-2tc-2sfx_firmware:*:*:*:*:*:*:*:* |
| phoenixcontact | fl_switch_2406-2sfx_firmware | < 3.50 | cpe:2.3:o:phoenixcontact:fl_switch_2406-2sfx_firmware:*:*:*:*:*:*:*:* |
| URL | タグ |
|---|---|
| https://certvde.com/de/advisories/VDE-2025-071 | Vendor Advisory |