Junglewise Threat Intelligence

CVE-2026-44090: Phoenix Contact CHARX SEC missing authentication in MQTT broker

CVE-2026-44090 · Severity: critical · CVSS 9.8 · Published 2026-07-30

Technologies: Phoenix Contact CHARX SEC-3050, Phoenix Contact CHARX SEC-3000, Phoenix Contact CHARX SEC-3150, Phoenix Contact CHARX SEC-3100. Vendors: Phoenix Contact.

Executive brief

Phoenix Contact CHARX SEC charging controllers, which manage electric vehicle charging stations, contain a security flaw where a critical internal communication component (the MQTT broker) lacks password protection. If an attacker bypasses the external firewall, they can gain full control over the charging controller. This could lead to a complete service outage, unauthorized access to charging data, or total device compromise.

Technical details

A missing authentication vulnerability (CWE-306) exists in the MQTT broker of Phoenix Contact CHARX SEC-3xxx series charging controllers. The broker is intended to be protected by an external firewall, but it does not implement its own authentication mechanisms. An unauthenticated remote attacker who can reach the broker over the network can interact with internal messaging, potentially leading to full system compromise. This issue is addressed in firmware version 1.9.1.

Affected products

  • Phoenix Contact CHARX SEC-3000 < 1.9.1
  • Phoenix Contact CHARX SEC-3050 < 1.9.1
  • Phoenix Contact CHARX SEC-3100 < 1.9.1
  • Phoenix Contact CHARX SEC-3150 < 1.9.1

Timeline

  • 2026-07-30: advisory: VDE-2026-008 published by CERT VDE
  • 2026-07-30: disclosed: CVE-2026-44090 published to NVD

References

Related threats