Phoenix Contact FL SWITCH Series Buffer Overflow Vulnerability Leading to Denial-of-Service

Vulnerability

A stack-based buffer overflow vulnerability has been identified in the file installation workflow of certain Phoenix Contact FL SWITCH devices. This vulnerability affects multiple models within the FL SWITCH 2xxx, FL SWITCH TSN 23xx, and FL SWITCH 59xx series, all running firmware prior to version 3.53. The issue allows a high-privileged attacker to send oversized POST parameters that overflow a fixed-size stack buffer in an internal process, causing a denial-of-service condition on the device.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the device to become unresponsive or to fail in its normal operations.

Remediation

Users are advised to update to the latest firmware version 3.53, which addresses this vulnerability.

Added: Mar 18, 2026, 8:30 AM
Updated: Mar 18, 2026, 8:30 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
0.6
exploitability
3.0
remediation
7.7
relevance
4.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.