Cyber Resilience

CVE-2025-41696

Exposed Creds in Phoenixcontact Fl Switch 2708 Pn Firmware ≤ 3.50

Published
09 December 2025
Modified
19 December 2025
CVSS Score v3.1 4.6
Click a component to see what it means
Raw vectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0019 9th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2025-41696 is a medium-severity Use of Hard-coded Credentials (CWE-798) vulnerability in Phoenixcontact Fl Switch 2303-8Sp1. Its CVSS base score is 4.6 (Medium).

Operationally, ranked at the 9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to PE-3 (Physical Access Control) and SC-41 (Port and I/O Device Access) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-41745Same product: Phoenixcontact Fl Nat 2008
CVE-2025-41695Same product: Phoenixcontact Fl Nat 2008
CVE-2025-41749Same product: Phoenixcontact Fl Nat 2008
CVE-2025-41693Same product: Phoenixcontact Fl Nat 2008
CVE-2025-41748Same product: Phoenixcontact Fl Nat 2008
CVE-2025-41692Same product: Phoenixcontact Fl Nat 2008
CVE-2025-41697Same product: Phoenixcontact Fl Nat 2008
CVE-2025-41750Same product: Phoenixcontact Fl Nat 2008
CVE-2025-41747Same product: Phoenixcontact Fl Nat 2008
CVE-2025-41752Same product: Phoenixcontact Fl Nat 2008

Affected Assets

phoenixcontact
fl switch 2708 pn firmware
≤ 3.50
phoenixcontact
fl switch 2708 firmware
≤ 3.50
phoenixcontact
fl switch 2608 pn firmware
≤ 3.50
phoenixcontact
fl switch 2608 firmware
≤ 3.50
phoenixcontact
fl switch 2516 pn firmware
≤ 3.50
phoenixcontact
fl switch 2516 firmware
≤ 3.50
phoenixcontact
fl switch 2514-2sfp pn firmware
≤ 3.50
phoenixcontact
fl switch 2514-2sfp firmware
≤ 3.50
phoenixcontact
fl switch 2512-2gc-2sfp firmware
≤ 3.50
phoenixcontact
fl switch 2508 pn firmware
≤ 3.50
+59 more product configuration(s) — see NVD for full list

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • SC-41 Port and I/O Device Access
  • PE-3 Physical Access Control
  • IA-5 Authenticator Management
Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly requires management of physical and logical access to system ports and I/O devices, blocking use of the undocumented UART.

prevent

Enforces physical access authorization and control over the device, preventing an attacker from reaching the PCB and UART.

prevent

Requires proper authenticator management, eliminating the hardcoded credentials that enable the UART side-channel read access.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.AA-01 partial match
prevents

PR.AA-01's credential/key-management processes can reduce the incentive to embed secrets but do not address or detect hard-coded values in source code, so the weakness remains fully possible.

PR.AA-02 none match
prevents

PR.AA-02 addresses human identity proofing and per-person credential issuance at enrollment; it has no bearing on whether developers embed static credentials in software.

PR.DS-01 none match
prevents

PR.DS-01 addresses encryption and integrity of stored data but never touches credential or key management practices, so it neither prevents hard-coded credentials nor removes any of their risk.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

Education on secure configuration practices discourages technical staff from embedding or relying on hard-coded credentials in systems and applications.

mitigates

Secure key-generation, distribution and storage procedures reduce the likelihood that hard-coded or default cryptographic keys will be introduced or left unprotected.

prevents

Explicit prohibition of hard-coded passwords and unauthenticated external services stops credentials from being embedded directly in source code.

prevents

Contractual requirements for secure coding practices and evidence of testing make it less likely that hard-coded credentials will be introduced or remain undetected in delivered code.

none

Requiring independent oversight and timely disabling of non-human identities makes it harder for hard-coded or long-lived credentials to remain exploitable.

none

Mandating immediate replacement of vendor-supplied default credentials eliminates the use of hard-coded or factory passwords that attackers can trivially obtain from documentation or firmware.

References