Phoenix Contact FL SWITCH Products Denial-of-Service Vulnerability via Stack-Based Buffer Overflow

Vulnerability

A stack-based buffer overflow vulnerability has been identified in Phoenix Contact FL SWITCH 2xxx, FL SWITCH TSN 23xx, and FL SWITCH 59xx firmware versions prior to 3.53. This vulnerability allows remote attackers with user privileges in the web UI to overwrite the TFTP filename setting using a POST request, leading to a denial-of-service condition.

Impact

Exploitation of this vulnerability causes a denial-of-service condition, disrupting the normal functionality of the affected device.

Remediation

Users are advised to update to the latest firmware version 3.53, which addresses this vulnerability.

Added: Mar 18, 2026, 8:35 AM
Updated: Mar 18, 2026, 8:35 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
0.6
exploitability
4.9
remediation
7.7
relevance
4.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.