Phoenix Contact’s Shocking Vulnerability Fix: QUINT4 UPS Gets a Power-Up!
Phoenix Contact patches five vulnerabilities in its QUINT4 UPS products, thwarting potential denial-of-service attacks and login credential thefts. While four flaws were patched, CVE-2025-41703 remains unaddressed for compatibility reasons. Isolated networks and firewalls are recommended to keep hackers from turning your uninterruptible power into a very interruptible power nap.

Hot Take:
Well, it looks like Phoenix Contact’s QUINT4 UPS had more open doors than a Black Friday sale! While the good folks at Phoenix have patched up these security potholes, it seems like one of the doors (CVE-2025-41703) is staying ajar because closing it would apparently disrupt legitimate UPS business. This is like having a guard dog that barks at intruders but also at the mailman. I guess for some vulnerabilities, it’s not just “close the gate” but more of a “keep calm and firewall on” situation.
Key Points:
- Phoenix Contact patched five vulnerabilities in QUINT4 UPS products.
- Four vulnerabilities can be exploited for DoS attacks.
- CVE-2025-41703 is a ‘denial of power service’ flaw that won’t be patched.
- CVE-2025-41705 can lead to password leakage in a MitM attack.
- Patches available in firmware version VC:07, except for CVE-2025-41703.
