CVE-2026-22320

MEDIUMCVSS 6.5/10EPSS 0.32%

Last modified

CVE-2026-22320 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Telnet/SSH access to trigger memory corruption by supplying unexpected or oversized filename input. Exploitation results in the corruption of the internal buffer, causing the CLI and web dashboard to become unavailable and leading to a denial of service.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.

Description

A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Telnet/SSH access to trigger memory corruption by supplying unexpected or oversized filename input. Exploitation results in the corruption of the internal buffer, causing the CLI and web dashboard to become unavailable and leading to a denial of service.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.32%

23.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
Phoenix ContactFL SWITCH 2005>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2008>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2016>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2105>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2108>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2116>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2204-2TC-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2205>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206-2FX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206-2FX SM>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206-2FX SM ST>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206-2FX ST>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206-2SFX PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206C-2FX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2207-FX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2207-FX SM>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2208>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2208 PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2208C>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2212-2TC-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2214-2FX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2214-2FX SM>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2214-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2214-2SFX PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2216>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2216 PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2304-2GC-2SFP>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2306-2SFP>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2306-2SFP PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2308>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2308 PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2312-2GC-2SFP>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2314-2SFP>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2314-2SFP PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2316>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2316 PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2404-2TC-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2406-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2406-2SFX PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2408>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2408 PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2412-2TC-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2414-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2414-2SFX PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2416>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2416 PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2504-2GC-2SFP>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2506-2SFP>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2506-2SFP PN>= 0.0.0, < 3.53

Showing 50 of 77 affected configurations. See the CNA advisory for the full list.

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-22320?
A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Telnet/SSH access to trigger memory corruption by supplying unexpected or oversized filename input. Exploitation results in the corruption of the internal buffer, causing the CLI and web dashboard to become unavailable and leading to a denial of service.
How severe is CVE-2026-22320?
CVE-2026-22320 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.32% probability of exploitation in the next 30 days.
How do I fix CVE-2026-22320?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-22320?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST