Executive brief
A security vulnerability exists in the network configuration scripts of Phoenix Contact CHARX electric vehicle charging controllers. This flaw allows a user with low-level access to the device to take complete control of the system by running commands with administrative (root) privileges. Such an exploit could lead to a total loss of device confidentiality and availability, potentially disrupting charging operations.
Technical details
An OS command injection vulnerability (CWE-78) exists in a network configuration script within the firmware of Phoenix Contact CHARX SEC-3xxx charging controllers. The vulnerability stems from the improper neutralization of special elements within the script, which can be exploited by a local attacker with low-level privileges. By providing malicious input to the script, the attacker can execute arbitrary commands with root-level permissions. This leads to a complete compromise of the device's confidentiality, integrity, and availability. The issue is addressed in firmware version 1.9.1.
Affected products
- Phoenix Contact CHARX SEC-3000 < 1.9.1
- Phoenix Contact CHARX SEC-3050 < 1.9.1
- Phoenix Contact CHARX SEC-3100 < 1.9.1
- Phoenix Contact CHARX SEC-3150 < 1.9.1
Timeline
- 2026-07-30: advisory: Advisory published by CERT VDE and NVD.
- 2026-07-30: disclosed