Junglewise Threat Intelligence

CVE-2026-7849: Phoenix Contact CHARX SEC command injection in system configuration

CVE-2026-7849 · Severity: critical · CVSS 9.8 · Published 2026-07-30

Executive brief

Phoenix Contact CHARX SEC charging controllers, used to manage electric vehicle (EV) charging stations, are vulnerable to a critical security flaw. An unauthenticated attacker can remotely inject malicious commands into the device's configuration, leading to full control over the controller. This could result in a complete shutdown of charging services, theft of sensitive data, or unauthorized modification of charging parameters.

Technical details

A command injection vulnerability (CWE-77) exists in the firmware of Phoenix Contact CHARX SEC-3xxx series charging controllers. The flaw stems from improper neutralization of special elements within the system configuration component. An unauthenticated remote attacker can exploit this by sending specially crafted input that is processed by the configuration engine, leading to arbitrary command execution with root privileges. The vulnerability affects firmware versions prior to 1.9.1. A patch has been released in firmware version 1.9.1 to address this issue.

Affected products

  • Phoenix Contact CHARX SEC-3000 1.0.0 to 1.9.1 (exclusive)
  • Phoenix Contact CHARX SEC-3050 1.0.0 to 1.9.1 (exclusive)
  • Phoenix Contact CHARX SEC-3100 1.0.0 to 1.9.1 (exclusive)
  • Phoenix Contact CHARX SEC-3150 1.0.0 to 1.9.1 (exclusive)

Timeline

  • 2026-07-30: advisory: Advisory VDE-2026-008 published by CERT VDE
  • 2026-07-30: patched: Firmware version 1.9.1 released to address the vulnerability

References

Related threats