{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/plcnext-engineer/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2025-41770"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PLCnext Engineer"],"_cs_severities":["low"],"_cs_tags":["dos","industrial-control-system","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Phoenix Contact"],"content_html":"\u003cp\u003eCVE-2025-41770 is a high-severity denial-of-service vulnerability discovered in the communication interface of Phoenix Contact's PLCnext Engineer software. The flaw allows an unauthenticated remote attacker to send specially crafted network traffic to the communication port used by the client application. Successful exploitation of this vulnerability interrupts the service, rendering the device unreachable via the PLCnext interface until a manual restart of the affected service is performed by an administrator. Because this vulnerability is accessible remotely without authentication, it presents a risk to industrial control environments where uptime is critical. Defenders should restrict network access to the PLCnext Engineer communication port to authorized management segments only.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a complete loss of service for the affected PLCnext Engineer communication interface. In an industrial or production environment, this interruption prevents operators from interacting with the PLCnext device via the client application, potentially impeding safety, monitoring, or control functions. The impact is persistent, requiring manual restart of the service, which could lead to significant operational downtime depending on the ease of physical or administrative access to the affected hardware.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement network segmentation to restrict access to the PLCnext Engineer communication port to known, trusted engineering workstations.\u003c/li\u003e\n\u003cli\u003eMonitor logs for repeated connection attempts or abnormal communication patterns directed at the PLCnext Engineer communication port.\u003c/li\u003e\n\u003cli\u003eReview Phoenix Contact security advisories for official patch releases and apply them to all vulnerable PLCnext Engineer deployments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T08:39:18Z","date_published":"2026-08-12T08:39:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2025-41770-plcnext-dos/","summary":"An unauthenticated remote denial-of-service vulnerability in the Phoenix Contact PLCnext Engineer communication interface allows attackers to crash the service, requiring manual intervention.","title":"Unauthenticated Denial-of-Service Vulnerability in PLCnext Engineer","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2025-41770-plcnext-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - PLCnext Engineer","version":"https://jsonfeed.org/version/1.1"}