Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

Plan PatchCVSS 9.8VDE-2025-056Aug 12, 2026
Phoenix ContactManufacturing
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Multiple improper input validation vulnerabilities in PLCnext firmware (versions 2019.0.4 through 2026.0.2) affect buffer handling, resource consumption, and SQL query processing. Unauthenticated attackers on the network can trigger denial of service, execute unexpected system behavior, or perform unauthorized SQL operations. These vulnerabilities impact availability, integrity, and confidentiality of PLCnext Control devices. Firmware version 2026.0.3 resolves all issues; EPC 1502 and EPC 1522 have no patch planned.

What this means
What could happen
An attacker without authentication could run commands on PLCnext controllers, disrupt operations through denial of service, or bypass access controls—affecting production lines, water treatment processes, or power distribution automation. Integrity and confidentiality of control logic and operational data are at risk.
Who's at risk
Manufacturing facilities and utilities using Phoenix Contact PLCnext controllers for process automation (VPLCNEXT CONTROL series, AXC F industrial controllers, BPC/RFC field controllers, and EPC edge devices). Water authorities and electric utilities with PLCnext-based SCADA or process control should prioritize updates.
How it could be exploited
An attacker with network access to a PLCnext device can send specially crafted input to trigger improper input validation, leading to buffer overflow (CWE-120), resource exhaustion (CWE-770), or SQL injection (CWE-89) without requiring authentication or user interaction.
Prerequisites
  • Network access to PLCnext device (HTTP/HTTPS ports)
  • No authentication or credentials required
  • Device running firmware version 2019.0.4 through 2026.0.2
remotely exploitableno authentication requiredlow complexityaffects industrial control systemsno patch available for EPC 1502/1522
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (17)
15 with fix2 EOL
ProductAffected VersionsFix Status
VPLCNEXT CONTROL 1000≥ 2019.0.4, < 2026.0.32026.0.3
VPLCNEXT CONTROL 2000≥ 2019.0.4, < 2026.0.32026.0.3
AXC F 1152≥ 2019.0.4, < 2026.0.32026.0.3
AXC F 1252≥ 2019.0.4, < 2026.0.32026.0.3
AXC F 2152≥ 2019.0.4, < 2026.0.32026.0.3
Remediation & Mitigation
0/5
Do now
0/2
EPC 1522
HARDENINGIsolate EPC 1502 and EPC 1522 from network access until vendor guidance is provided, as no patch is available
All products
WORKAROUNDRestrict network access to PLCnext devices using firewall rules; allow only trusted engineering workstations and SCADA/control networks
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate all affected PLCnext devices to firmware version 2026.0.3 or later
HARDENINGMonitor PLCnext device logs for unexpected input patterns or denial of service events
Mitigations - no patch available
0/1
The following products have reached End of Life with no planned fix: EPC 1522, EPC 1502. Apply the following compensating controls:
HARDENINGImplement network segmentation to prevent untrusted networks from reaching PLCnext devices
API: /api/v1/advisories/a3f0e87b-28f4-4544-9427-29ed518e3334

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware | CVSS 9.8 - OTPulse