Phoenix Contact FL SWITCH 2005
- < 3.53
- 3.50
A command injection vulnerability has been identified in the Phoenix Contact FL SWITCH 2xxx, FL SWITCH TSN 23xx, and FL SWITCH 59xx firmware prior to version 3.53. This vulnerability allows a high-privileged attacker to send crafted HTTP POST requests that execute arbitrary commands on the underlying Linux operating system with root privileges.
Exploitation of this vulnerability allows for arbitrary command execution on the device's Linux operating system with root privileges.
Users are advised to update to the latest firmware version 3.53, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.