A vulnerability was found in Phoenix Contact AXC F 1152, AXC F 1252, AXC F 2000 EA, AXC F 2152, AXC F 3152, BPC 9102S, BPC 9202S, RFC 4072R, RFC 4072S, VL3 UPC 2440 EDGE, VPLCNEXT CONTROL 1000, VPLCNEXT CONTROL 2000, VPLCNEXT CONTROL 3000, VPLCNEXT CONTROL 500, Catan C1, EPC 1502 and EPC 1522 up to 2026.0.2. It has been classified as critical. The impacted element is an unknown function of the component Web Interface. The manipulation leads to sql injection.

This vulnerability is uniquely identified as CVE-2025-41771. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is recommended.