📦 Fl Switch 2316\/k1 Firmware

by Phoenixcontact

🔍 What is Fl Switch 2316\/k1 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-41748

HIGH CVSS 7.1 Dec 9, 2025

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_Dot1xCfg.php allows attackers to trick authenticated users into clicking malicious links, enabling unauthorized changes to device con...

CVE-2025-41749

HIGH CVSS 7.1 Dec 9, 2025

An unauthenticated cross-site scripting (XSS) vulnerability in port_util.php allows attackers to trick authenticated users into clicking malicious links, enabling unauthorized changes to device config...

CVE-2025-41750

HIGH CVSS 7.1 Dec 9, 2025

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_PortCfg.php allows attackers to trick authenticated users into clicking malicious links, enabling unauthorized changes to device conf...

CVE-2025-41751

HIGH CVSS 7.1 Dec 9, 2025

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_portCntr.php allows attackers to trick authenticated users into clicking malicious links that modify device configuration parameters ...

CVE-2025-41752

HIGH CVSS 7.1 Dec 9, 2025

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_portSfp.php allows attackers to trick authenticated users into clicking malicious links that modify device configuration parameters v...

CVE-2025-41745

HIGH CVSS 7.1 Dec 9, 2025

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_portCntr2.php allows attackers to trick authenticated users into sending malicious POST requests that modify device configuration par...

CVE-2025-41746

HIGH CVSS 7.1 Dec 9, 2025

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_portSecCfg.php allows attackers to trick authenticated users into sending malicious POST requests that modify device configuration pa...

CVE-2025-41747

HIGH CVSS 7.1 Dec 9, 2025

An unauthenticated cross-site scripting (XSS) vulnerability in pxc_vlanIntfCfg.php allows attackers to trick authenticated users into sending malicious POST requests that modify device configuration p...

CVE-2025-41695

HIGH CVSS 7.1 Dec 9, 2025

An unauthenticated cross-site scripting (XSS) vulnerability in dyn_conn.php allows attackers to trick authenticated users into sending malicious POST requests that modify device configuration paramete...

CVE-2025-41696

MEDIUM CVSS 4.6 Dec 9, 2025

This vulnerability allows attackers to use an undocumented UART port on the PCB as a side-channel to gain read access to parts of the device's filesystem. Attackers must first obtain hardcoded credent...

CVE-2025-41697

MEDIUM CVSS 6.8 Dec 9, 2025

This vulnerability allows attackers to exploit an undocumented UART port on printed circuit boards as a side-channel attack vector to gain root access, typically after obtaining credentials through CV...

CVE-2025-41692

MEDIUM CVSS 6.8 Dec 9, 2025

This vulnerability allows a high-privileged remote attacker with webUI admin access to brute-force the underlying OS root and user passwords due to weak password generation. Affected systems are those...

CVE-2025-41693

MEDIUM CVSS 4.3 Dec 9, 2025

A low-privileged remote attacker can exploit SSH functionality to execute commands after authentication, causing resource exhaustion that degrades management performance. This affects systems with vul...

CVE-2025-41694

MEDIUM CVSS 6.5 Dec 9, 2025

A low-privileged remote attacker can send a webshell request with an empty command containing whitespace, causing the web server to block while waiting for more data. This creates a denial-of-service ...