Junglewise Threat Intelligence

CVE-2026-44101: Phoenix Contact CHARX SEC-3xxx missing authentication in OCPP Agent

CVE-2026-44101 · Severity: critical · CVSS 9.8 · Published 2026-07-30

Technologies: Phoenix Contact CHARX SEC-3050, Phoenix Contact CHARX SEC-3000, Phoenix Contact CHARX SEC-3150, Phoenix Contact CHARX SEC-3100. Vendors: Phoenix Contact.

Executive brief

Phoenix Contact CHARX charging controllers, used to manage electric vehicle (EV) charging stations, contain a security flaw in their communication service. An unauthorized person can remotely change the device's backend connection settings without a password. This could allow an attacker to disrupt charging services or intercept sensitive data transmitted by the controller.

Technical details

The vulnerability is classified as Missing Authentication for Critical Function (CWE-306) within the CHARX OCPP Agent service. This service is responsible for handling the Open Charge Point Protocol (OCPP) communications on Phoenix Contact CHARX SEC-3xxx series charging controllers. An unauthenticated remote attacker can exploit this lack of authentication to reconfigure the backend connection settings. Successful exploitation can result in a Denial-of-Service (DoS) by redirecting traffic or the disclosure of confidential data to an attacker-controlled server. The issue is addressed in firmware version 1.9.1.

Affected products

  • Phoenix Contact CHARX SEC-3000 1.0.0 to 1.9.1 (exclusive)
  • Phoenix Contact CHARX SEC-3050 1.0.0 to 1.9.1 (exclusive)
  • Phoenix Contact CHARX SEC-3100 1.0.0 to 1.9.1 (exclusive)
  • Phoenix Contact CHARX SEC-3150 1.0.0 to 1.9.1 (exclusive)

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory

References

Related threats