Critical severity9.6NVD Advisory· Published Aug 8, 2023· Updated Jun 17, 2026
CVE-2023-3526
CVE-2023-3526
Description
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17- cpe:2.3:o:phoenixcontact:cloud_client_1101t-tx_firmware:*:*:*:*:*:*:*:*Range: <2.06.10
- cpe:2.3:o:phoenixcontact:tc_cloud_client_1002-4g_att_firmware:*:*:*:*:*:*:*:*Range: <2.07.2
- cpe:2.3:o:phoenixcontact:tc_cloud_client_1002-4g_firmware:*:*:*:*:*:*:*:*Range: <2.07.2
- cpe:2.3:o:phoenixcontact:tc_cloud_client_1002-4g_vzw_firmware:*:*:*:*:*:*:*:*Range: <2.07.2
- cpe:2.3:o:phoenixcontact:tc_router_3002t-4g_att_firmware:*:*:*:*:*:*:*:*Range: <2.07.2
- cpe:2.3:o:phoenixcontact:tc_router_3002t-4g_firmware:*:*:*:*:*:*:*:*Range: <2.07.2
- cpe:2.3:o:phoenixcontact:tc_router_3002t-4g_vzw_firmware:*:*:*:*:*:*:*:*Range: <2.07.2
- Range: <2.07.2
<2.07.2+ 1 more
- (no CPE)range: <2.07.2
- (no CPE)range: 0
<2.06.10+ 1 more
- (no CPE)range: <2.06.10
- (no CPE)range: 0
0+ 1 more
- (no CPE)range: 0
- (no CPE)range: 0
0+ 2 more
- (no CPE)range: 0
- (no CPE)range: 0
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.