VulnSea

fl_switch_2316_pn_firmware vulnerabilities

CVEs whose affected-version data names the fl_switch_2316_pn_firmware package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

14 CVEsRSS

CVE-2025-41752High· 7.1
9mo ago

An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM)…

An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM)…

▾ Twilightphoenixcontact · fl_nat_2008_firmwareEPSS 9.8%via NVD
CVE-2025-41751High· 7.1
9mo ago

An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM…

An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM…

▾ Twilightphoenixcontact · fl_nat_2008_firmwareEPSS 9.8%via NVD
CVE-2025-41750High· 7.1
9mo ago

An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM)…

An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM)…

▾ Twilightphoenixcontact · fl_switch_2008f_firmwareEPSS 9.8%via NVD
CVE-2025-41749High· 7.1
9mo ago

An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM)

An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). …

▾ Twilightphoenixcontact · fl_switch_2008f_firmwareEPSS 0.65%via NVD
CVE-2025-41748High· 7.1
9mo ago

An XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM…

An XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM…

▾ Twilightphoenixcontact · fl_nat_2008_firmwareEPSS 9.8%via NVD
CVE-2025-41747High· 7.1
9mo ago

An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based managemen…

An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based managemen…

▾ Twilightphoenixcontact · fl_nat_2008_firmwareEPSS 9.8%via NVD
CVE-2025-41746High· 7.1
9mo ago

An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management…

An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management…

▾ Twilightphoenixcontact · fl_switch_2406-2sfx_pn_firmwareEPSS 9.8%via NVD
CVE-2025-41745High· 7.1
9mo ago

An XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management …

An XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management …

▾ Twilightphoenixcontact · fl_nat_2008_firmwareEPSS 0.65%via NVD
CVE-2025-41697Medium· 6.8
9mo ago

An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g

An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692.

▾ Sunlitphoenixcontact · fl_switch_2708_pn_firmwareEPSS 0.24%via NVD
CVE-2025-41696Medium· 4.6
9mo ago

An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device.

An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device.

▾ Sunlitphoenixcontact · fl_switch_2708_pn_firmwareEPSS 0.21%via NVD
CVE-2025-41695High· 7.1
9mo ago

An XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM)…

An XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM)…

▾ Twilightphoenixcontact · fl_nat_2008_firmwareEPSS 0.66%via NVD
CVE-2025-41694Medium· 6.5
9mo ago

A low privileged remote attacker can run the webshell with an empty command containing whitespace

A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block until it receives more data, resulting in a DoS condition of the websserver.

▾ Sunlitphoenixcontact · fl_switch_2708_pn_firmwareEPSS 0.48%via NVD
CVE-2025-41693Medium· 4.3
9mo ago

A low privileged remote attacker can use the ssh feature to execute commands directly after login

A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses resources which leads to a reduced performance of the management functions. Switching functionality is not…

▾ Sunlitphoenixcontact · fl_switch_2708_pn_firmwareEPSS 0.52%via NVD
CVE-2025-41692Medium· 6.8
9mo ago

A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm.

A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm.

▾ Sunlitphoenixcontact · fl_switch_2708_pn_firmwareEPSS 0.30%via NVD
fl_switch_2316_pn_firmware vulnerabilities (CVEs) · VulnSea