Phoenix Contact Vulnerabilities and Affected Products
Vulnerabilities associated with CHARX SEC-3100.
Products
Clear product- CHARX SEC-300051 vulnerabilities
- CHARX SEC-305051 vulnerabilities
- CHARX SEC-310051 vulnerabilities
- CHARX SEC-315051 vulnerabilities
- FL NAT 200822 vulnerabilities
- FL NAT 220822 vulnerabilities
- FL NAT 2304-2GC-2SFP22 vulnerabilities
- FL SWITCH 200522 vulnerabilities
- FL SWITCH 200822 vulnerabilities
- FL SWITCH 2008F22 vulnerabilities
- FL SWITCH 201622 vulnerabilities
- FL SWITCH 210522 vulnerabilities
- FL SWITCH 210822 vulnerabilities
- FL SWITCH 211622 vulnerabilities
- FL SWITCH 2204-2TC-2SFX22 vulnerabilities
- FL SWITCH 220522 vulnerabilities
- FL SWITCH 2206-2FX22 vulnerabilities
- FL SWITCH 2206-2FX SM22 vulnerabilities
- FL SWITCH 2206-2FX SM ST22 vulnerabilities
- FL SWITCH 2206-2FX ST22 vulnerabilities
- FL SWITCH 2206-2SFX22 vulnerabilities
- FL SWITCH 2206-2SFX PN22 vulnerabilities
- FL SWITCH 2206C-2FX22 vulnerabilities
- FL SWITCH 2207-FX22 vulnerabilities
- FL SWITCH 2207-FX SM22 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-7849CRITICAL | Command Injection in SCM (idledisconnect parameter)Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root. CWE-77Jul 30, 2026 | CVSS9.3v4.0 | EPSS0.419% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44108CRITICAL | Firewall bypass during shutdownDue to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise. CWE-696Jul 30, 2026 | CVSS9.3v4.0 | EPSS0.462% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44107HIGH | Exposed Reboot via ModbusA reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack. CWE-749Jul 30, 2026 | CVSS8.7v4.0 | EPSS0.309% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44105MEDIUM | Cleartext password in logsThe credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted. CWE-532Jul 30, 2026 | CVSS5.8v4.0 | EPSS0.094% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44106HIGH | Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website fileA privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. CWE-78Jul 30, 2026 | CVSS8.5v4.0 | EPSS0.232% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44104CRITICAL | ControllerAgent does not perform validation of firmwareThe firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise. CWE-347Jul 30, 2026 | CVSS9.3v4.0 | EPSS0.241% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44103MEDIUM | JupiCore does not perform validation of firmwareAn unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104. CWE-434Jul 30, 2026 | CVSS6.9v4.0 | EPSS0.236% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44102MEDIUM | OCPP Firmware download is not properly lockedAn unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process. CWE-362Jul 30, 2026 | CVSS6.9v4.0 | EPSS0.209% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44101CRITICAL | OCPP reconfiguration vulnerabilityDue to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker. CWE-306Jul 30, 2026 | CVSS9.3v4.0 | EPSS0.401% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44100HIGH | JupiCore charging point reconfiguration without authThe CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering. CWE-306Jul 30, 2026 | CVSS8.8v4.0 | EPSS0.277% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44099HIGH | Local Privilege Escalation via pppd password injectionA privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. CWE-78Jul 30, 2026 | CVSS8.5v4.0 | EPSS0.232% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44098HIGH | OS Command Injection in OCPP Agent via charge_box_idThis vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted. CWE-78Jul 30, 2026 | CVSS8.8v4.0 | EPSS1.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44097MEDIUM | File Upload vulnerabilityA low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service. CWE-434Jul 30, 2026 | CVSS5.3v4.0 | EPSS0.244% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44096HIGH | udhcpc Privilege EscalationA privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise. CWE-78Jul 30, 2026 | CVSS8.5v4.0 | EPSS0.232% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44095HIGH | Local Privilege Escalation via Network scriptsA privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. CWE-78Jul 30, 2026 | CVSS8.5v4.0 | EPSS0.232% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44094HIGH | Fallback to second RAUC slot with default credentialsAn unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted. CWE-636Jul 30, 2026 | CVSS8.3v4.0 | EPSS0.258% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44093HIGH | Local Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start scriptA local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. CWE-78Jul 30, 2026 | CVSS8.5v4.0 | EPSS0.232% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44092HIGH | Missing input validation / stripping of CRLF characters in SystemConfigManagerAn unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss. CWE-93Jul 30, 2026 | CVSS8.8v4.0 | EPSS0.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44091HIGH | Creation of a new configuration by posting a malicious ID to MQTTAn unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss. CWE-501Jul 30, 2026 | CVSS8.8v4.0 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44090CRITICAL | Missing authentication for MQTT BrokerDue to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised. CWE-306Jul 30, 2026 | CVSS9.3v4.0 | EPSS0.401% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-41032HIGH | Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllersIt is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information. CWE-200Jun 3, 2026 | CVSS7.5v3.1 | EPSS0.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41699HIGH | Phoenix Contact: Security Advisory for CHARX SEC-3xxx charging controllersAn low privileged remote attacker with an account for the Web-based management can change the system configuration to perform a command injection as root, resulting in a total loss of confidentiality, availability and integrity due to improper control of generation of code ('Code Injection'). CWE-94Oct 14, 2025 | CVSS8.8v3.1 | EPSS0.869% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-25271HIGH | OCPP Backend Configuration via Insecure DefaultsAn unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface. CWE-1188Jul 8, 2025 | CVSS8.8v3.1 | EPSS0.288% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-25270CRITICAL | Remote Code Execution via Unauthenticated Configuration ManipulationAn unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations. CWE-913Jul 8, 2025 | CVSS9.8v3.1 | EPSS0.631% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-25269HIGH | Local Privilege Escalation via Unauthenticated Command InjectionAn unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation. CWE-78Jul 8, 2025 | CVSS8.4v3.1 | EPSS0.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |