← Back to CVE List
CVE-2025-25269NVD
Vulnerability Summary
An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.
CVSS v3.1 Base Metrics — Score 8.4 (HIGH)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Phoenixcontact Charx Sec-3000 Firmware < 1.7.3
- Phoenixcontact Charx Sec-3050 Firmware < 1.7.3
- Phoenixcontact Charx Sec-3100 Firmware < 1.7.3
- Phoenixcontact Charx Sec-3150 Firmware < 1.7.3
- Phoenixcontact Charx Sec-3000 Firmware 1.7.3
- Phoenixcontact Charx Sec-3050 Firmware 1.7.3
- Phoenixcontact Charx Sec-3100 Firmware 1.7.3
- Phoenixcontact Charx Sec-3150 Firmware 1.7.3