Junglewise Threat Intelligence

CVE-2026-44091: Phoenix Contact CHARX SEC trust boundary violation in MQTT Broker

CVE-2026-44091 · Severity: critical · CVSS 9.1 · Published 2026-07-30

Technologies: Phoenix Contact CHARX SEC-3050, Phoenix Contact CHARX SEC-3000, Phoenix Contact CHARX SEC-3150, Phoenix Contact CHARX SEC-3100. Vendors: Phoenix Contact.

Executive brief

Phoenix Contact CHARX SEC charging controllers, used in electric vehicle charging infrastructure, are vulnerable to unauthorized configuration changes. An attacker can remotely inject malicious data into the system's internal messaging service to create new configuration entries. This could allow an attacker to disrupt charging operations or compromise the integrity of the device's settings.

Technical details

A trust boundary violation (CWE-501) exists in Phoenix Contact CHARX SEC-3xxx firmware versions prior to 1.9.1. The vulnerability allows an unauthenticated remote attacker to publish a malicious ID to the internal MQTT broker. This action results in the unauthorized creation of new configuration entries within the system configuration. Successful exploitation can lead to a loss of system integrity and availability, potentially disrupting charging services. The issue is addressed in firmware version 1.9.1.

Affected products

  • Phoenix Contact CHARX SEC-3000 1.0.0 to 1.9.1 (exclusive)
  • Phoenix Contact CHARX SEC-3050 1.0.0 to 1.9.1 (exclusive)
  • Phoenix Contact CHARX SEC-3100 1.0.0 to 1.9.1 (exclusive)
  • Phoenix Contact CHARX SEC-3150 1.0.0 to 1.9.1 (exclusive)

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory

References

Related threats