Executive brief
Phoenix Contact CHARX electric vehicle charging controllers contain a security flaw where login credentials for a specific user account are recorded in system log files. An attacker who already has limited access to the device could read these logs to gain higher-level access via SSH. This could allow an unauthorized person to disrupt the vehicle charging process or interfere with device operations.
Technical details
This vulnerability is classified as an insertion of sensitive information into log files (CWE-532). The firmware for CHARX SEC-3xxx charging controllers incorrectly writes the credentials for the 'user-app' account into system logs. A local attacker with low-privileged access to the file system or log services can retrieve these credentials to authenticate via SSH as the 'user-app' user. This level of access can be used to interrupt charging services or as a stepping stone for further privilege escalation. The issue is resolved in firmware version 1.9.1.
Affected products
- Phoenix Contact CHARX SEC-3000 1.0.0 to 1.9.0
- Phoenix Contact CHARX SEC-3050 1.0.0 to 1.9.0
- Phoenix Contact CHARX SEC-3100 1.0.0 to 1.9.0
- Phoenix Contact CHARX SEC-3150 1.0.0 to 1.9.0
Timeline
- 2026-07-30: disclosed
- 2026-07-30: advisory