Description
An low privileged remote attacker with an account for the Web-based management can change the system configuration to perform a command injection as root, resulting in a total loss of confidentiality, availability and integrity due to improper control of generation of code ('Code Injection').
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
0.0.0 before 1.7.4
0.0.0 before 1.7.4
0.0.0 before 1.7.4
0.0.0 before 1.7.4
Credits
X from JPCERT
References
phoenixcontact.csaf-tp.certvde.com/...2025/vde-2025-074.json