Skip to content
Threat Feed
low advisory

Unauthenticated Denial-of-Service Vulnerability in PLCnext Engineer

An unauthenticated remote denial-of-service vulnerability in the Phoenix Contact PLCnext Engineer communication interface allows attackers to crash the service, requiring manual intervention.

CVE search metadata

CVE search record: CVE-2025-41770. Severity: high. CVSS: 7.5. KEV: no. Product: PLCnext Engineer. Brief: Unauthenticated Denial-of-Service Vulnerability in PLCnext Engineer. Brief link: https://feed.craftedsignal.io/briefs/2026-08-cve-2025-41770-plcnext-dos/

CVE-2025-41770 is a high-severity denial-of-service vulnerability discovered in the communication interface of Phoenix Contact's PLCnext Engineer software. The flaw allows an unauthenticated remote attacker to send specially crafted network traffic to the communication port used by the client application. Successful exploitation of this vulnerability interrupts the service, rendering the device unreachable via the PLCnext interface until a manual restart of the affected service is performed by an administrator. Because this vulnerability is accessible remotely without authentication, it presents a risk to industrial control environments where uptime is critical. Defenders should restrict network access to the PLCnext Engineer communication port to authorized management segments only.

Impact

The vulnerability results in a complete loss of service for the affected PLCnext Engineer communication interface. In an industrial or production environment, this interruption prevents operators from interacting with the PLCnext device via the client application, potentially impeding safety, monitoring, or control functions. The impact is persistent, requiring manual restart of the service, which could lead to significant operational downtime depending on the ease of physical or administrative access to the affected hardware.

Recommendation

  • Implement network segmentation to restrict access to the PLCnext Engineer communication port to known, trusted engineering workstations.
  • Monitor logs for repeated connection attempts or abnormal communication patterns directed at the PLCnext Engineer communication port.
  • Review Phoenix Contact security advisories for official patch releases and apply them to all vulnerable PLCnext Engineer deployments.

Immediate actions

Restrict network access to PLCnext Engineer communication ports

IT Operations 24h

Mitigations

Apply firmware or software patches from Phoenix Contact

immediate IT Operations

CVE-2025-41770