CVE-2025-25268 | Phoenix Contact CHARX SEC-3000 up to 1.7.2 API Endpoint missing authentication (VDE-2025-019)
A vulnerability classified as critical has been found in Phoenix Contact CHARX SEC-3150, CHARX SEC-3100, CHARX SEC-3050 and CHARX SEC-3000 up to 1.7.2. Affected is an unknown function of the component API Endpoint. The manipulation leads to missing authentication.
This vulnerability is traded as CVE-2025-25268. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.