Executive brief
Phoenix Contact CHARX charging controllers, which manage electric vehicle charging stations, are vulnerable to a remote attack. An attacker who gains control over the management backend can execute unauthorized commands on the controller. This could lead to the interruption of vehicle charging services and unauthorized access to the device's operating system.
Technical details
An OS command injection vulnerability (CWE-78) exists in the firmware of Phoenix Contact CHARX SEC-3xxx charging controllers. The flaw is reachable by an unauthenticated remote attacker who has gained control over the Open Charge Point Protocol (OCPP) backend or can bypass the firewall to reach the service. Successful exploitation allows the execution of arbitrary commands as the limited user 'charx-oa'. This can result in a loss of availability (interruption of charging) and partial loss of confidentiality and integrity. The vulnerability is addressed in firmware version 1.9.1.
Affected products
- Phoenix Contact CHARX SEC-3000 1.0.0 to 1.9.1
- Phoenix Contact CHARX SEC-3050 1.0.0 to 1.9.1
- Phoenix Contact CHARX SEC-3100 1.0.0 to 1.9.1
- Phoenix Contact CHARX SEC-3150 1.0.0 to 1.9.1
Timeline
- 2026-07-30: advisory: VDE-2026-008 published by CERT VDE
- 2026-07-30: patched: Firmware version 1.9.1 released to address the issue