CVE-2025-41707 is a denial-of-service vulnerability affecting the websocket handler in Phoenix Contact UPS devices. An unauthenticated remote attacker can trigger this issue by sending a specially crafted websocket message, leading to a denial of service without impacting core functionality. Rated as MEDIUM severity with a CVSS score of 5.3, it requires no user interaction and has low attack complexity. There is currently no public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in CISA's KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Phoenix Contact | QUINT4-UPS/24DC/24DC/10/EIP | >= VC:00, < VC:07CNA affecteddefault unaffected | |
| Phoenix Contact | QUINT4-UPS/24DC/24DC/20/EIP | >= VC:00, < VC:07CNA affecteddefault unaffected | |
| Phoenix Contact | QUINT4-UPS/24DC/24DC/40/EIP | >= VC:00, < VC:07CNA affecteddefault unaffected | |
| Phoenix Contact | QUINT4-UPS/24DC/24DC/5/EIP | >= VC:00, < VC:07CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.