Executive brief
Phoenix Contact CHARX SEC charging controllers, which manage electric vehicle charging stations, contain a vulnerability that allows an attacker to force the device into an insecure state. By triggering a fallback to an older firmware version, an attacker can gain unauthorized access to the system using default credentials. This could lead to the interruption of vehicle charging services and unauthorized access to the device's operating system.
Technical details
The vulnerability is classified as a 'Failing Open' (CWE-636) flaw within the firmware management of Phoenix Contact CHARX SEC-3xxx devices. An unauthenticated remote attacker can manipulate the system to trigger a fallback mechanism to a secondary firmware partition. This secondary partition contains an insecure configuration, specifically default credentials for the 'user-app' account. Successful exploitation allows the attacker to establish an SSH connection to the device, potentially leading to a denial-of-service for charging operations and further lateral movement or system tampering. The issue is addressed in firmware version 1.9.1.
Affected products
- Phoenix Contact CHARX SEC-3000 Firmware < 1.9.1
- Phoenix Contact CHARX SEC-3050 Firmware < 1.9.1
- Phoenix Contact CHARX SEC-3100 Firmware < 1.9.1
- Phoenix Contact CHARX SEC-3150 Firmware < 1.9.1
Timeline
- 2026-07-30: advisory
- 2026-07-30: patched