An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://certvde.com/de/advisories/VDE-2025-071 |
|
History
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phoenixcontact
Phoenixcontact fl Nat 2208 Phoenixcontact fl Nat 2304-2gc-2sfp Phoenixcontact fl Switch 2005 Phoenixcontact fl Switch 2008 Phoenixcontact fl Switch 2008f Phoenixcontact fl Switch 2016 Phoenixcontact fl Switch 2105 Phoenixcontact fl Switch 2108 Phoenixcontact fl Switch 2116 Phoenixcontact fl Switch 2204-2tc-2sfx Phoenixcontact fl Switch 2205 Phoenixcontact fl Switch 2206-2fx Phoenixcontact fl Switch 2206-2fx Sm Phoenixcontact fl Switch 2206-2fx Sm St Phoenixcontact fl Switch 2206-2sfx Phoenixcontact fl Switch 2206-2sfx Pn Phoenixcontact fl Switch 2206c-2fx Phoenixcontact fl Switch 2207-fx Phoenixcontact fl Switch 2207-fx Sm Phoenixcontact fl Switch 2208 Phoenixcontact fl Switch 2208 Pn Phoenixcontact fl Switch 2208c Phoenixcontact fl Switch 2212-2tc-2sfx Phoenixcontact fl Switch 2214-2fx Phoenixcontact fl Switch 2214-2fx Sm Phoenixcontact fl Switch 2214-2sfx Phoenixcontact fl Switch 2214-2sfx Pn Phoenixcontact fl Switch 2216 Phoenixcontact fl Switch 2216 Pn Phoenixcontact fl Switch 2304-2gc-2sfp Phoenixcontact fl Switch 2306-2sfp Phoenixcontact fl Switch 2306-2sfp Pn Phoenixcontact fl Switch 2308 Phoenixcontact fl Switch 2308 Pn Phoenixcontact fl Switch 2312-2gc-2sfp Phoenixcontact fl Switch 2314-2sfp Phoenixcontact fl Switch 2314-2sfp Pn Phoenixcontact fl Switch 2316 Phoenixcontact fl Switch 2316/k1 Phoenixcontact fl Switch 2316 Pn Phoenixcontact fl Switch 2404-2tc-2sfx Phoenixcontact fl Switch 2406-2sfx Phoenixcontact fl Switch 2406-2sfx Pn Phoenixcontact fl Switch 2408 Phoenixcontact fl Switch 2408 Pn Phoenixcontact fl Switch 2412-2tc-2sfx Phoenixcontact fl Switch 2414-2sfx Phoenixcontact fl Switch 2414-2sfx Pn Phoenixcontact fl Switch 2416 Phoenixcontact fl Switch 2416 Pn Phoenixcontact fl Switch 2504-2gc-2sfp Phoenixcontact fl Switch 2506-2sfp Phoenixcontact fl Switch 2506-2sfp/k1 Phoenixcontact fl Switch 2506-2sfp Pn Phoenixcontact fl Switch 2508 Phoenixcontact fl Switch 2508/k1 Phoenixcontact fl Switch 2508 Pn Phoenixcontact fl Switch 2512-2gc-2sfp Phoenixcontact fl Switch 2514-2sfp Phoenixcontact fl Switch 2514-2sfp Pn Phoenixcontact fl Switch 2516 Phoenixcontact fl Switch 2516 Pn Phoenixcontact fl Switch 2608 Phoenixcontact fl Switch 2608 Pn Phoenixcontact fl Switch 2708 Phoenixcontact fl Switch 2708 Pn |
|
| Vendors & Products |
Phoenixcontact
Phoenixcontact fl Nat 2208 Phoenixcontact fl Nat 2304-2gc-2sfp Phoenixcontact fl Switch 2005 Phoenixcontact fl Switch 2008 Phoenixcontact fl Switch 2008f Phoenixcontact fl Switch 2016 Phoenixcontact fl Switch 2105 Phoenixcontact fl Switch 2108 Phoenixcontact fl Switch 2116 Phoenixcontact fl Switch 2204-2tc-2sfx Phoenixcontact fl Switch 2205 Phoenixcontact fl Switch 2206-2fx Phoenixcontact fl Switch 2206-2fx Sm Phoenixcontact fl Switch 2206-2fx Sm St Phoenixcontact fl Switch 2206-2sfx Phoenixcontact fl Switch 2206-2sfx Pn Phoenixcontact fl Switch 2206c-2fx Phoenixcontact fl Switch 2207-fx Phoenixcontact fl Switch 2207-fx Sm Phoenixcontact fl Switch 2208 Phoenixcontact fl Switch 2208 Pn Phoenixcontact fl Switch 2208c Phoenixcontact fl Switch 2212-2tc-2sfx Phoenixcontact fl Switch 2214-2fx Phoenixcontact fl Switch 2214-2fx Sm Phoenixcontact fl Switch 2214-2sfx Phoenixcontact fl Switch 2214-2sfx Pn Phoenixcontact fl Switch 2216 Phoenixcontact fl Switch 2216 Pn Phoenixcontact fl Switch 2304-2gc-2sfp Phoenixcontact fl Switch 2306-2sfp Phoenixcontact fl Switch 2306-2sfp Pn Phoenixcontact fl Switch 2308 Phoenixcontact fl Switch 2308 Pn Phoenixcontact fl Switch 2312-2gc-2sfp Phoenixcontact fl Switch 2314-2sfp Phoenixcontact fl Switch 2314-2sfp Pn Phoenixcontact fl Switch 2316 Phoenixcontact fl Switch 2316/k1 Phoenixcontact fl Switch 2316 Pn Phoenixcontact fl Switch 2404-2tc-2sfx Phoenixcontact fl Switch 2406-2sfx Phoenixcontact fl Switch 2406-2sfx Pn Phoenixcontact fl Switch 2408 Phoenixcontact fl Switch 2408 Pn Phoenixcontact fl Switch 2412-2tc-2sfx Phoenixcontact fl Switch 2414-2sfx Phoenixcontact fl Switch 2414-2sfx Pn Phoenixcontact fl Switch 2416 Phoenixcontact fl Switch 2416 Pn Phoenixcontact fl Switch 2504-2gc-2sfp Phoenixcontact fl Switch 2506-2sfp Phoenixcontact fl Switch 2506-2sfp/k1 Phoenixcontact fl Switch 2506-2sfp Pn Phoenixcontact fl Switch 2508 Phoenixcontact fl Switch 2508/k1 Phoenixcontact fl Switch 2508 Pn Phoenixcontact fl Switch 2512-2gc-2sfp Phoenixcontact fl Switch 2514-2sfp Phoenixcontact fl Switch 2514-2sfp Pn Phoenixcontact fl Switch 2516 Phoenixcontact fl Switch 2516 Pn Phoenixcontact fl Switch 2608 Phoenixcontact fl Switch 2608 Pn Phoenixcontact fl Switch 2708 Phoenixcontact fl Switch 2708 Pn |
Tue, 09 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user. | |
| Title | Reflected XSS vulnerability in pxc_vlanIntfCfg.php | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-12-09T08:09:26.183Z
Updated: 2025-12-09T16:01:33.796Z
Reserved: 2025-04-16T11:18:45.758Z
Link: CVE-2025-41747
Updated: 2025-12-09T14:22:00.532Z
Status : Awaiting Analysis
Published: 2025-12-09T16:17:49.827
Modified: 2025-12-09T18:36:53.557
Link: CVE-2025-41747
No data.