Executive brief
A security flaw exists in the startup scripts of Phoenix Contact CHARX electric vehicle charging controllers. This vulnerability allows a person with low-level access to the device to take complete control of the system as a root user. An attacker could use this to disrupt charging operations, steal data, or permanently disable the controller.
Technical details
This vulnerability is classified as an OS Command Injection (CWE-78) within the init-script responsible for user-applications in Phoenix Contact CHARX SEC-3xxx firmware. A local attacker with low-privileged access can exploit improper neutralization of special elements within the script to execute arbitrary commands with root privileges. Successful exploitation leads to a total loss of confidentiality, integrity, and availability. The issue affects firmware versions prior to 1.9.1, where a fix has been implemented.
Affected products
- Phoenix Contact CHARX SEC-3000 1.0.0 to 1.9.1 (exclusive)
- Phoenix Contact CHARX SEC-3050 1.0.0 to 1.9.1 (exclusive)
- Phoenix Contact CHARX SEC-3100 1.0.0 to 1.9.1 (exclusive)
- Phoenix Contact CHARX SEC-3150 1.0.0 to 1.9.1 (exclusive)
Timeline
- 2026-07-30: advisory: Advisory published by CERT VDE and NVD
- 2026-07-30: patched: Firmware version 1.9.1 released to address the issue