CVE-2026-22321

MEDIUMCVSS 5.3/10EPSS 0.37%

Last modified

CVE-2026-22321 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A stack-based buffer overflow in the device's Telnet/SSH CLI login routine occurs when a unauthenticated attacker send an oversized or unexpected username input. An overflow condition crashes the thread handling the login attempt, forcing the session to close. EPSS estimates a 0.37% chance of exploitation in the next 30 days.

Description

A stack-based buffer overflow in the device's Telnet/SSH CLI login routine occurs when a unauthenticated attacker send an oversized or unexpected username input. An overflow condition crashes the thread handling the login attempt, forcing the session to close. Because other CLI sessions remain unaffected, the impact is limited to a low‑severity availability disruption.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS Probability
0.37%

28.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
Phoenix ContactFL SWITCH 2005>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2008>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2016>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2105>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2108>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2116>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2204-2TC-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2205>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206-2FX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206-2FX SM>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206-2FX SM ST>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206-2FX ST>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206-2SFX PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2206C-2FX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2207-FX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2207-FX SM>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2208>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2208 PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2208C>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2212-2TC-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2214-2FX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2214-2FX SM>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2214-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2214-2SFX PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2216>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2216 PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2304-2GC-2SFP>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2306-2SFP>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2306-2SFP PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2308>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2308 PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2312-2GC-2SFP>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2314-2SFP>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2314-2SFP PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2316>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2316 PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2404-2TC-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2406-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2406-2SFX PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2408>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2408 PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2412-2TC-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2414-2SFX>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2414-2SFX PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2416>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2416 PN>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2504-2GC-2SFP>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2506-2SFP>= 0.0.0, < 3.53
Phoenix ContactFL SWITCH 2506-2SFP PN>= 0.0.0, < 3.53

Showing 50 of 77 affected configurations. See the CNA advisory for the full list.

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-22321?
A stack-based buffer overflow in the device's Telnet/SSH CLI login routine occurs when a unauthenticated attacker send an oversized or unexpected username input. An overflow condition crashes the thread handling the login attempt, forcing the session to close. Because other CLI sessions remain unaffected, the impact is limited to a low‑severity availability disruption.
How severe is CVE-2026-22321?
CVE-2026-22321 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.37% probability of exploitation in the next 30 days.
How do I fix CVE-2026-22321?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-22321?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST