CVE Vulnerabilities

CVE-2025-25270

Improper Control of Dynamically-Managed Code Resources

Published: Jul 08, 2025 | Modified: Jul 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.

Weakness

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

Affected Software

Name Vendor Start Version End Version
Charx_sec-3000_firmware Phoenixcontact * 1.7.3 (excluding)

Potential Mitigations

References