Junglewise Threat Intelligence

CVE-2026-44099: Phoenix Contact CHARX SEC privilege escalation in system configuration

CVE-2026-44099 · Severity: high · CVSS 7.8 · Published 2026-07-30

Technologies: Phoenix Contact CHARX SEC-3050, Phoenix Contact CHARX SEC-3000, Phoenix Contact CHARX SEC-3150, Phoenix Contact CHARX SEC-3100. Vendors: Phoenix Contact.

Executive brief

A security vulnerability exists in Phoenix Contact CHARX electric vehicle charging controllers, which manage and monitor EV charging processes. A user with low-level access to the device can exploit a flaw in the system configuration to gain full administrative (root) control. This could allow an attacker to disrupt charging operations, modify device settings, or compromise the entire system.

Technical details

An OS command injection vulnerability (CWE-78) exists within the system configuration component of Phoenix Contact CHARX SEC-3xxx firmware. The flaw stems from improper neutralization of special elements, which allows a local attacker with low-privileged access to inject and execute arbitrary commands with root privileges. This vulnerability leads to a complete compromise of confidentiality, integrity, and availability (CIA) for the affected charging controller. The issue is resolved in firmware version 1.9.1.

Affected products

  • Phoenix Contact CHARX SEC-3000 Firmware < 1.9.1
  • Phoenix Contact CHARX SEC-3050 Firmware < 1.9.1
  • Phoenix Contact CHARX SEC-3100 Firmware < 1.9.1
  • Phoenix Contact, CHARX SEC-3150 Firmware < 1.9.1

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory

References

Related threats