Executive brief
Phoenix Contact CHARX charging controllers, used to manage electric vehicle (EV) charging stations, contain a security flaw in their communication service. An unauthorized person can remotely change the device's backend connection settings without a password. This could allow an attacker to disrupt charging services or intercept sensitive data transmitted by the controller.
Technical details
The vulnerability is classified as Missing Authentication for Critical Function (CWE-306) within the CHARX OCPP Agent service. This service is responsible for handling the Open Charge Point Protocol (OCPP) communications on Phoenix Contact CHARX SEC-3xxx series charging controllers. An unauthenticated remote attacker can exploit this lack of authentication to reconfigure the backend connection settings. Successful exploitation can result in a Denial-of-Service (DoS) by redirecting traffic or the disclosure of confidential data to an attacker-controlled server. The issue is addressed in firmware version 1.9.1.
Affected products
- Phoenix Contact CHARX SEC-3000 1.0.0 to 1.9.1 (exclusive)
- Phoenix Contact CHARX SEC-3050 1.0.0 to 1.9.1 (exclusive)
- Phoenix Contact CHARX SEC-3100 1.0.0 to 1.9.1 (exclusive)
- Phoenix Contact CHARX SEC-3150 1.0.0 to 1.9.1 (exclusive)
Timeline
- 2026-07-30: disclosed
- 2026-07-30: advisory