An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials for the Webfrontend.
https://www.securityweek.com/vulnerabilities-allow-disruption-of-phoenix-contact-ups-devices/
https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-34146