
Phoenix Contact patched three PLCnext flaws, including CVE-2025-41771, which lets an attacker execute unauthorized SQL queries, plus a CVSS 9.8 RCE bug. #PhoenixContact #PLCnext #SQLInjection #CVE202541771 #ICS #OTSecurity #Cybersecurity https://securityonline.info/phoenix-contact-plcnext-sql-injection/
Post summary
Phoenix Contact has released patches for three PLCnext flaws, including CVE‑2025‑41771, which involves SQL injection and a high‑severity RCE vulnerability, with no indications of active exploitation or PoC availability.
