---
id: CVE-2025-41770
title: >-
  An unauthenticated denial-of-service vulnerability in the device's PLCnext
  Engineer communication interface allow an remote attacker to interrupt access
  via the client application
summary: >-
  An unauthenticated denial-of-service vulnerability in the device's PLCnext
  Engineer communication interface allow an remote attacker to interrupt access
  via the client application. Successful exploitation prevents communication
  until the…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
published: '2026-08-12'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T11:10:00.150'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-41770'
references:
  - url: >-
      https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json
    label: info@cert.vde.com
tags:
  - nvd
ingestedAt: '2026-09-29T11:32:41.234Z'
---

## Overview

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
