Executive brief
A security vulnerability exists in Phoenix Contact CHARX electric vehicle charging controllers. A user with limited access to the device can exploit a flaw in the network configuration component to gain full administrative control. This could allow an attacker to disrupt charging operations, modify device settings, or compromise the entire system.
Technical details
This vulnerability is classified as an OS Command Injection (CWE-78) within the udhcpc DHCP client component. A local attacker with low-privileged access (specifically the 'charx-web' user) can exploit improper neutralization of special elements to execute arbitrary commands with root privileges. This leads to a full system compromise of the charging controller. The issue affects CHARX SEC-3000, 3050, 3100, and 3150 models running firmware versions prior to 1.9.1. A patch is available in firmware version 1.9.1.
Affected products
- Phoenix Contact CHARX SEC-3000 < 1.9.1
- Phoenix Contact CHARX SEC-3050 < 1.9.1
- Phoenix Contact CHARX SEC-3100 < 1.9.1
- Phoenix Contact CHARX SEC-3150 < 1.9.1
Timeline
- 2026-07-30: advisory: VDE-2026-008 published by CERT VDE
- 2026-07-30: disclosed: CVE-2026-44096 published to NVD