Junglewise Threat Intelligence

CVE-2026-44108: Phoenix Contact CHARX SEC-3xxx firewall bypass during shutdown

CVE-2026-44108 · Severity: critical · CVSS 9.8 · Published 2026-07-30

Executive brief

Phoenix Contact CHARX charging controllers, used to manage electric vehicle charging stations, contain a flaw in how they shut down. During the power-off process, the firewall stops protecting the device before other internal services are closed, creating a brief window of vulnerability. An attacker could exploit this timing to bypass security controls and gain full control over the charging controller, potentially leading to data theft or service disruption.

Technical details

This vulnerability is classified as Incorrect Behavior Order (CWE-696) within the shutdown sequence of the CHARX SEC-3xxx firmware. During system shutdown, the firewall service is terminated before internal services (such as MQTT or OCPP agents) are stopped. This creates a race condition where a remote, unauthenticated attacker can connect to these normally protected services during the shutdown window. Successful exploitation can lead to full system compromise, including unauthorized reconfiguration or command execution. The issue is resolved in firmware version 1.9.1.

Affected products

  • Phoenix Contact CHARX SEC-3000 < 1.9.1
  • Phoenix Contact CHARX SEC-3050 < 1.9.1
  • Phoenix Contact: CHARX SEC-3100 < 1.9.1
  • Phoenix Contact CHARX SEC-3150 < 1.9.1

Timeline

  • 2026-07-30: advisory: Advisory published by CERT VDE and Phoenix Contact
  • 2026-07-30: patched: Firmware version 1.9.1 released to address the issue

References

Related threats