Executive brief
Phoenix Contact CHARX charging controllers, which manage electric vehicle charging stations, contain a flaw that allows them to be remotely rebooted. An unauthorized person on the network can trigger this reboot without needing a password, causing the charging station to stop working. This results in a denial-of-service that prevents vehicles from charging until the system recovers.
Technical details
The CharxModbusServer component in Phoenix Contact CHARX SEC-3xxx charging controllers exposes a dangerous method or function via Modbus TCP. An unauthenticated remote attacker can send a specific Modbus command to the listening port to trigger a system reboot. This vulnerability (CWE-749) is accessible whenever Modbus functionality is enabled and the port is reachable over the network. Successful exploitation results in a Denial-of-Service (DoS) condition. The issue is addressed in firmware version 1.9.1.
Affected products
- Phoenix Contact CHARX SEC-3000 1.0.0 to 1.9.1 (exclusive)
- Phoenix Contact CHARX SEC-3050 1.0.0 to 1.9.1 (exclusive)
- Phoenix Contact CHARX SEC-3100 1.0.0 to 1.9.1 (exclusive)
- Phoenix Contact CHARX SEC-3150 1.0.0 to 1.9.1 (exclusive)
Timeline
- 2026-07-30: disclosed
- 2026-07-30: advisory
- 2026-07-30: patched: Fixed in firmware version 1.9.1