Executive brief
Phoenix Contact CHARX SEC charging controllers, which manage electric vehicle charging stations, are affected by a race condition during firmware updates. An unauthenticated attacker can trigger a download of an invalid firmware file, which remains accessible on the device for a short period due to improper cleanup. This could allow an attacker to interfere with the device's file system or integrity during the update process.
Technical details
A race condition (CWE-362) exists in the firmware update cleanup process of Phoenix Contact CHARX SEC-3xxx devices. An unauthenticated remote attacker can initiate a firmware download via the Open Charge Point Protocol (OCPP) backend by providing an invalid firmware file. Due to improper locking during the cleanup phase, the invalid file is not immediately deleted, leaving a window of time where the file remains accessible on the system. This vulnerability affects firmware versions prior to 1.9.1. An attacker can exploit this to impact the integrity of the device's storage or potentially facilitate further attacks during the update window.
Affected products
- Phoenix Contact CHARX SEC-3000 < 1.9.1
- Phoenix Contact CHARX SEC-3050 < 1.9.1
- Phoenix Contact CHARX SEC-3100 < 1.9.1
- Phoenix Contact CHARX SEC-3150 < 1.9.1
Timeline
- 2026-07-30: advisory: VDE-2026-008 published by CERT VDE
- 2026-07-30: disclosed: CVE-2026-44102 published