product of phoenixcontact

fl switch 2206-2sfx

14 thingsrelated by NVD
Severity

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the…
CVE-2025-41752
Severity high
An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the…
CVE-2025-41751
Severity high
An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the…
CVE-2025-41750
Severity high
An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link…
CVE-2025-41749
Severity high
An XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the…
CVE-2025-41748
Severity high
An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a…
CVE-2025-41747
Severity high
An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a…
CVE-2025-41746
Severity high
An XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a…
CVE-2025-41745
Severity high
An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from…
CVE-2025-41697
Severity medium
An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692…
CVE-2025-41696
Severity medium
An XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated…
CVE-2025-41695
Severity high
A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block until it…
CVE-2025-41694
Severity medium
A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses…
CVE-2025-41693
Severity medium
A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS…
CVE-2025-41692
Severity medium