Junglewise Threat Intelligence

CVE-2026-44100: Phoenix Contact CHARX SEC JupiCore missing authentication

CVE-2026-44100 · Severity: critical · CVSS 9.4 · Published 2026-07-30

Technologies: Phoenix Contact CHARX SEC-3050, Phoenix Contact CHARX SEC-3000, Phoenix Contact CHARX SEC-3150, Phoenix Contact CHARX SEC-3100. Vendors: Phoenix Contact.

Executive brief

Phoenix Contact CHARX SEC charging controllers, which manage electric vehicle charging stations, contain a security flaw in their JupiCore service. An unauthorized person can remotely reconfigure charging points without needing a password. This could allow an attacker to disrupt charging services, tamper with system files, or access sensitive charging point identifiers.

Technical details

A missing authentication vulnerability (CWE-306) exists in the JupiCore service of Phoenix Contact CHARX SEC-3xxx charging controllers. An unauthenticated remote attacker can exploit this flaw to reconfigure charging points via the network. Successful exploitation can lead to the disclosure of charging point Unique Identifiers (UIDs), file tampering, and a denial-of-service (DoS) condition. The vulnerability is addressed in firmware version 1.9.1.

Affected products

  • Phoenix Contact CHARX SEC-3000 Firmware < 1.9.1
  • Phoenix Contact CHARX SEC-3050 Firmware < 1.9.1
  • Phoenix Contact: CHARX SEC-3100 Firmware < 1.9.1
  • Phoenix Contact CHARX SEC-3150 Firmware < 1.9.1

Timeline

  • 2026-07-30: advisory: VDE-2026-008 published by CERT VDE
  • 2026-07-30: patched: Firmware version 1.9.1 released to address the issue

References

Related threats