Junglewise Threat Intelligence

CVE-2026-44106: Phoenix Contact CHARX SEC-3xxx privilege escalation in init-script

CVE-2026-44106 · Severity: high · CVSS 7.8 · Published 2026-07-30

Executive brief

A security flaw exists in the startup scripts of Phoenix Contact CHARX electric vehicle charging controllers. This vulnerability allows a person with low-level access to the device to take complete control of the system as a root user. An attacker could use this to disrupt charging operations, steal data, or permanently disable the controller.

Technical details

This vulnerability is classified as an OS Command Injection (CWE-78) within the init-script responsible for user-applications in Phoenix Contact CHARX SEC-3xxx firmware. A local attacker with low-privileged access can exploit improper neutralization of special elements within the script to execute arbitrary commands with root privileges. Successful exploitation leads to a total loss of confidentiality, integrity, and availability. The issue affects firmware versions prior to 1.9.1, where a fix has been implemented.

Affected products

  • Phoenix Contact CHARX SEC-3000 1.0.0 to 1.9.1 (exclusive)
  • Phoenix Contact CHARX SEC-3050 1.0.0 to 1.9.1 (exclusive)
  • Phoenix Contact CHARX SEC-3100 1.0.0 to 1.9.1 (exclusive)
  • Phoenix Contact CHARX SEC-3150 1.0.0 to 1.9.1 (exclusive)

Timeline

  • 2026-07-30: advisory: Advisory published by CERT VDE and NVD
  • 2026-07-30: patched: Firmware version 1.9.1 released to address the issue

References

Related threats