Junglewise Threat Intelligence

CVE-2026-44097: Phoenix Contact CHARX SEC unrestricted file upload in firmware REST endpoint

CVE-2026-44097 · Severity: high · CVSS 7.1 · Published 2026-07-30

Technologies: Phoenix Contact CHARX SEC-3050, Phoenix Contact CHARX SEC-3000, Phoenix Contact CHARX SEC-3150, Phoenix Contact CHARX SEC-3100. Vendors: Phoenix Contact.

Executive brief

Phoenix Contact CHARX SEC charging controllers, which manage electric vehicle charging stations, contain a vulnerability in their firmware update interface. An attacker with basic 'operator' access can upload unauthorized files to the device's storage. This could allow an attacker to fill up the device's memory, potentially causing the charging station to crash or become unavailable for use.

Technical details

The vulnerability is classified as Unrestricted Upload of File with Dangerous Type (CWE-434) within the REST API endpoint used for firmware updates. A remote attacker authenticated with 'operator' privileges can bypass intended file type restrictions to upload arbitrary files to the device's persistent storage. While the advisory does not explicitly confirm remote code execution, the primary impact is integrity loss and availability loss due to resource exhaustion (disk space). The issue affects CHARX SEC-3xxx series controllers with firmware versions prior to 1.9.1. Users are advised to update to firmware version 1.9.1 or later.

Affected products

  • Phoenix Contact CHARX SEC-3000 Firmware < 1.9.1
  • Phoenix Contact CHARX SEC-3050 Firmware < 1.9.1
  • Phoenix Contact CHARX SEC-3100 Firmware < 1.9.1
  • Phoenix Contact CHARX SEC-3150 Firmware < 1.9.1

Timeline

  • 2026-07-30: advisory: VDE-2026-008 published by CERT VDE
  • 2026-07-30: disclosed: CVE-2026-44097 published to NVD

References

Related threats