Phoenix Contact FL SWITCH 2xxx Undocumented UART Port Side-Channel Vulnerability for Root Access

Vulnerability

A vulnerability exists in Phoenix Contact FL SWITCH 2xxx firmware versions prior to 3.50, allowing an unauthenticated physical attacker to gain root access through an undocumented UART port on the PCB. This access can be achieved by using credentials obtained from another vulnerability, CVE-2025-41692.

Impact

Exploitation of this vulnerability provides unauthorized root access to the device.

Remediation

Users are advised to update to the latest FL SWITCH 2xxx firmware version 3.50, which addresses this vulnerability.

Added: Dec 9, 2025, 7:54 PM
Updated: Dec 9, 2025, 7:54 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.