Executive brief
Phoenix Contact CHARX SEC-3xxx controllers are used to manage electric vehicle (EV) charging stations. A security vulnerability in these controllers allows an unauthorized person on the same network to download system log files. This could lead to the exposure of sensitive operational data or configuration details, potentially aiding further attacks on the charging infrastructure.
Technical details
A vulnerability classified as Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) exists in the firmware of Phoenix Contact CHARX SEC-3xxx charging controllers. The flaw allows an unauthenticated attacker with network access (specifically adjacent network access according to the summary, though the CVSS vector indicates Network) to download system log files without providing credentials. This occurs due to insufficient access control on the log retrieval endpoint. Successful exploitation can result in the disclosure of restricted information contained within the logs. The issue is resolved in firmware version 1.9.0.
Affected products
- Phoenix Contact CHARX SEC-3000 < 1.9.0
- Phoenix Contact CHARX SEC-3050 < 1.9.0
- Phoenix Contact CHARX SEC-3100 < 1.9.0
- Phoenix Contact CHARX SEC-3150 < 1.9.0
Timeline
- 2026-06-03: disclosed: Initial advisory release by CERT@VDE and Phoenix Contact
- 2026-06-03: patched: Firmware version 1.9.0 released to address the issue