Junglewise Threat Intelligence

CVE-2026-44103: Phoenix Contact CHARX SEC firmware integrity bypass in JupiCore

CVE-2026-44103 · Severity: medium · CVSS 5.3 · Published 2026-07-30

Executive brief

Phoenix Contact CHARX SEC-3xxx devices are controllers used to manage electric vehicle (EV) charging stations. A security flaw in these controllers allows an unauthorized person to remotely install malicious software onto the internal charging module. This could allow an attacker to tamper with the device's operations or compromise its integrity, potentially disrupting charging services.

Technical details

The Phoenix Contact CHARX SEC-3xxx series charging controllers contain a vulnerability in the JupiCore service. The service fails to perform integrity or verification checks (such as cryptographic signatures) on firmware updates transmitted to the internal charging module. An unauthenticated remote attacker can exploit this lack of verification to inject and execute malicious firmware. This vulnerability can be chained with other flaws, such as CVE-2026-44104, to further compromise the device. The issue is resolved in firmware version 1.9.1.

Affected products

  • Phoenix Contact CHARX SEC-3000 Firmware < 1.9.1
  • Phoenix Contact CHARX SEC-3050 Firmware < 1.9.1
  • Phoenix Contact CHARX SEC-3100 Firmware < 1.9.1
  • Phoenix Contact CHARX SEC-3150 Firmware < 1.9.1

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory
  • 2026-07-30: patched: Fixed in firmware version 1.9.1

References

Related threats