{"id":29523,"date":"2025-12-09T12:26:07","date_gmt":"2025-12-09T12:26:07","guid":{"rendered":"http:\/\/localhost\/?p=29523"},"modified":"2025-12-09T12:26:07","modified_gmt":"2025-12-09T12:26:07","slug":"hardcoded-user-password","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=29523","title":{"rendered":"Hardcoded User Password_CVE-2025-41696"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device.&#8221;,&#8221;published&#8221;:&#8221;2025-12-09T08:13:22.783Z&#8221;,&#8221;modified&#8221;:&#8221;2025-12-09T08:13:22.783Z&#8221;,&#8221;type&#8221;:&#8221;cve&#8221;,&#8221;title&#8221;:&#8221;Hardcoded User Password&#8221;,&#8221;source&#8221;:&#8221;CERTVDE&#8221;,&#8221;references&#8221;:&#8221;https:\/\/certvde.com\/de\/advisories\/VDE-2025-071&#8243;,&#8221;id&#8221;:&#8221;CVE-2025-41696&#8243;,&#8221;bulletinFamily&#8221;:&#8221;&#8221;,&#8221;cwe&#8221;:[&#8220;CWE-798&#8243;],&#8221;cvelist&#8221;:null,&#8221;sourceData&#8221;:&#8221;Phoenix Contact FL SWITCH 2005 0.0.0\\nPhoenix Contact FL SWITCH 2008 0.0.0\\nPhoenix Contact FL SWITCH 2016 0.0.0\\nPhoenix Contact FL SWITCH 2105 0.0.0\\nPhoenix Contact FL SWITCH 2108 0.0.0\\nPhoenix Contact FL SWITCH 2116 0.0.0\\nPhoenix Contact FL SWITCH 2204-2TC-2SFX 0.0.0\\nPhoenix Contact FL SWITCH 2205 0.0.0\\nPhoenix Contact FL SWITCH 2206-2FX 0.0.0\\nPhoenix Contact FL SWITCH 2206-2FX SM 0.0.0\\nPhoenix Contact FL SWITCH 2206-2FX SM ST 0.0.0\\nPhoenix Contact FL SWITCH 2206-2FX ST 0.0.0\\nPhoenix Contact FL SWITCH 2206-2SFX 0.0.0\\nPhoenix Contact FL SWITCH 2206-2SFX PN 0.0.0\\nPhoenix Contact FL SWITCH 2206C-2FX 0.0.0\\nPhoenix Contact FL SWITCH 2207-FX 0.0.0\\nPhoenix Contact FL SWITCH 2207-FX SM 0.0.0\\nPhoenix Contact FL SWITCH 2208 0.0.0\\nPhoenix Contact FL SWITCH 2208 PN 0.0.0\\nPhoenix Contact FL SWITCH 2208C 0.0.0\\nPhoenix Contact FL SWITCH 2212-2TC-2SFX 0.0.0\\nPhoenix Contact FL SWITCH 2214-2FX 0.0.0\\nPhoenix Contact FL SWITCH 2214-2FX SM 0.0.0\\nPhoenix Contact FL SWITCH 2214-2SFX 0.0.0\\nPhoenix Contact FL SWITCH 2214-2SFX PN 0.0.0\\nPhoenix Contact FL SWITCH 2216 0.0.0\\nPhoenix Contact FL SWITCH 2216 PN 0.0.0\\nPhoenix Contact FL SWITCH 2304-2GC-2SFP 0.0.0\\nPhoenix Contact FL SWITCH 2306-2SFP 0.0.0\\nPhoenix Contact FL SWITCH 2306-2SFP PN 0.0.0\\nPhoenix Contact FL SWITCH 2308 0.0.0\\nPhoenix Contact FL SWITCH 2308 PN 0.0.0\\nPhoenix Contact FL SWITCH 2312-2GC-2SFP 0.0.0\\nPhoenix Contact FL SWITCH 2314-2SFP 0.0.0\\nPhoenix Contact FL SWITCH 2314-2SFP PN 0.0.0\\nPhoenix Contact FL SWITCH 2316 0.0.0\\nPhoenix Contact FL SWITCH 2316 PN 0.0.0\\nPhoenix Contact FL SWITCH 2404-2TC-2SFX 0.0.0\\nPhoenix Contact FL SWITCH 2406-2SFX 0.0.0\\nPhoenix Contact FL SWITCH 2406-2SFX PN 0.0.0\\nPhoenix Contact FL SWITCH 2408 0.0.0\\nPhoenix Contact FL SWITCH 2408 PN 0.0.0\\nPhoenix Contact FL SWITCH 2412-2TC-2SFX 0.0.0\\nPhoenix Contact FL SWITCH 2414-2SFX 0.0.0\\nPhoenix Contact FL SWITCH 2414-2SFX PN 0.0.0\\nPhoenix Contact FL SWITCH 2416 0.0.0\\nPhoenix Contact FL SWITCH 2416 PN 0.0.0\\nPhoenix Contact FL SWITCH 2504-2GC-2SFP 0.0.0\\nPhoenix Contact FL SWITCH 2506-2SFP 0.0.0\\nPhoenix Contact FL SWITCH 2506-2SFP PN 0.0.0\\nPhoenix Contact FL SWITCH 2508 0.0.0\\nPhoenix Contact FL SWITCH 2508 PN 0.0.0\\nPhoenix Contact FL SWITCH 2512-2GC-2SFP 0.0.0\\nPhoenix Contact FL SWITCH 2514-2SFP 0.0.0\\nPhoenix Contact FL SWITCH 2514-2SFP PN 0.0.0\\nPhoenix Contact FL SWITCH 2516 0.0.0\\nPhoenix Contact FL SWITCH 2516 PN 0.0.0\\nPhoenix Contact FL SWITCH 2608 0.0.0\\nPhoenix Contact FL SWITCH 2608 PN 0.0.0\\nPhoenix Contact FL SWITCH 2708 0.0.0\\nPhoenix Contact FL SWITCH 2708 PN 0.0.0\\nPhoenix Contact FL SWITCH 2303-8SP1 0.0.0\\nPhoenix Contact FL NAT 2008 0.0.0\\nPhoenix Contact FL NAT 2208 0.0.0\\nPhoenix Contact FL NAT 2304-2GC-2SFP 0.0.0\\nPhoenix Contact FL SWITCH 2008F 0.0.0\\nPhoenix Contact FL SWITCH 2316\/K1 0.0.0\\nPhoenix Contact FL SWITCH 2506-2SFP\/K1 0.0.0\\nPhoenix Contact FL SWITCH 2508\/K1 0.0.0&#8243;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:4.6,&#8221;severity&#8221;:&#8221;MEDIUM&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:P\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;&#8221;,&#8221;category_name&#8221;:&#8221;CVE&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;FL SWITCH 2005&#8243;,&#8221;version&#8221;:&#8221;0.0.0&#8243;,&#8221;vendor&#8221;:&#8221;Phoenix Contact&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[6,8,67,12,21,13,7,11,5],"class_list":["post-29523","post","type-post","status-publish","format-standard","hentry","category-category_cve","tag-cve","tag-cvss","tag-cvss-46","tag-exploit","tag-medium","tag-news","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hardcoded User Password_CVE-2025-41696 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=29523\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hardcoded User Password_CVE-2025-41696 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=29523\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-09T12:26:07+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29523#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29523\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Hardcoded User Password_CVE-2025-41696\",\"datePublished\":\"2025-12-09T12:26:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29523\"},\"wordCount\":537,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-4.6\",\"exploit\",\"MEDIUM\",\"news\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_cve\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=29523#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29523\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29523\",\"name\":\"Hardcoded User Password_CVE-2025-41696 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-12-09T12:26:07+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29523#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=29523\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29523#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hardcoded User Password_CVE-2025-41696\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hardcoded User Password_CVE-2025-41696 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=29523","og_locale":"en_US","og_type":"article","og_title":"Hardcoded User Password_CVE-2025-41696 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read...","og_url":"https:\/\/zero.redgem.net\/?p=29523","og_site_name":"zero redgem","article_published_time":"2025-12-09T12:26:07+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=29523#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=29523"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Hardcoded User Password_CVE-2025-41696","datePublished":"2025-12-09T12:26:07+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=29523"},"wordCount":537,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-4.6","exploit","MEDIUM","news","Security","tapic","Vulnerability"],"articleSection":["category_cve"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=29523#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=29523","url":"https:\/\/zero.redgem.net\/?p=29523","name":"Hardcoded User Password_CVE-2025-41696 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-12-09T12:26:07+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=29523#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=29523"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=29523#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Hardcoded User Password_CVE-2025-41696"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/29523","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=29523"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/29523\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=29523"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=29523"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=29523"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}