Phoenix Contact FL SWITCH 2xxx Undocumented UART Port Side-Channel Vulnerability

Vulnerability

A vulnerability exists in Phoenix Contact FL SWITCH 2xxx firmware versions prior to 3.50, allowing an attacker to exploit an undocumented UART port on the PCB. By using user hardcoded credentials obtained from another vulnerability (CVE-2025-41692), the attacker can gain read access to certain parts of the device's filesystem.

Impact

Exploitation of this vulnerability could lead to unauthorized read access of the device's filesystem.

Remediation

Users are advised to update to the latest FL SWITCH 2xxx firmware version 3.50, which addresses this vulnerability.

Added: Dec 9, 2025, 7:57 PM
Updated: Dec 9, 2025, 7:57 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
2.1
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.