Executive brief
Phoenix Contact CHARX charging controllers, which manage electric vehicle charging stations, are vulnerable to a remote attack. An unauthenticated attacker can inject malicious data into the device's communication system, potentially disrupting charging operations or altering system settings. This could lead to service outages or unauthorized changes to how the charging station functions.
Technical details
The ModbusServer application in Phoenix Contact CHARX SEC-3xxx firmware fails to properly validate input fetched from the MQTT broker. This vulnerability is classified as a CRLF injection (CWE-93), where an unauthenticated remote attacker can inject malicious sequences into the application. The attack vector is over the network and requires no user interaction or prior authentication. Successful exploitation can lead to a loss of integrity and availability of the charging controller. The issue is addressed in firmware version 1.9.1.
Affected products
- Phoenix Contact CHARX SEC-3000 Firmware < 1.9.1
- Phoenix Contact CHARX SEC-3050 Firmware < 1.9.1
- Phoenix Contact CHARX SEC-3100 Firmware < 1.9.1
- Phoenix Contact CHARX SEC-3150 Firmware < 1.9.1
Timeline
- 2026-07-30: advisory
- 2026-07-30: patched: Fixed in firmware version 1.9.1