VYPR

FL NAT 2208

by Phoenixcontact

CVEs (24)

  • CVE-2026-22319MedMar 18, 2026
    risk 0.32cvss 4.9epss 0.00

    A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send oversized POST parameters that overflow a fixed-size stack buffer within an internal process, resulting in a DoS attack.

  • CVE-2026-22318MedMar 18, 2026
    risk 0.32cvss 4.9epss 0.00

    A stack-based buffer overflow vulnerability in the device's file transfer parameter workflow allows a high-privileged attacker to send oversized POST parameters, causing memory corruption in an internal process, resulting in a DoS attack.

  • CVE-2025-41696MedDec 9, 2025
    risk 0.30cvss 4.6epss 0.00

    An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device.

  • CVE-2025-41693MedDec 9, 2025
    risk 0.28cvss 4.3epss 0.01

    A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses resources which leads to a reduced performance of the management functions. Switching functionality is not affected.

Page 2 of 2