Junglewise Threat Intelligence

CVE-2026-44093: Phoenix Contact CHARX SEC-3xxx privilege escalation in init-script

CVE-2026-44093 · Severity: high · CVSS 7.8 · Published 2026-07-30

Technologies: Phoenix Contact CHARX SEC-3050, Phoenix Contact CHARX SEC-3000, Phoenix Contact CHARX SEC-3150, Phoenix Contact CHARX SEC-3100. Vendors: Phoenix Contact.

Executive brief

A security vulnerability has been identified in Phoenix Contact CHARX electric vehicle charging controllers. This flaw allows an individual who already has limited access to the device's operating system to gain full administrative (root) control. If exploited, an attacker could completely take over the charging controller, potentially disrupting charging operations or accessing sensitive configuration data.

Technical details

This vulnerability is classified as an OS Command Injection (CWE-78) within the init-script responsible for user-applications in Phoenix Contact CHARX SEC-3xxx firmware. The root cause is the improper neutralization of special elements within the script, which allows a local attacker with low-level privileges to inject and execute arbitrary commands with root authority. The attack requires local access to the device's shell or environment. Successful exploitation leads to a complete compromise of confidentiality, integrity, and availability. The issue is resolved in firmware version 1.9.1 and later.

Affected products

  • Phoenix Contact CHARX SEC-3000 Firmware < 1.9.1
  • Phoenix Contact CHARX SEC-3050 Firmware < 1.9.1
  • Phoenix Contact CHARX SEC-3100 Firmware < 1.9.1
  • Phoenix Contact CHARX SEC-3150 Firmware < 1.9.1

Timeline

  • 2026-07-30: advisory: VDE-2026-008 published by CERT VDE
  • 2026-07-30: disclosed: CVE-2026-44093 published to NVD

References

Related threats