Technology · Phoenix Contact
Phoenix Contact CHARX SEC-3100 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 20 vulnerabilities in Phoenix Contact CHARX SEC-3100: 0 in the last 7 days and 19 in the last 90 days, 8 of them critical and 0 exploited in the wild. The most recent, CVE-2026-7849, was published on 30 July 2026.
- Last 7 days
- 0
- Last 90 days
- 19
- Critical, all time
- 8
- Exploited in the wild
- 0
About Phoenix Contact CHARX SEC-3100
Firmware for the CHARX SEC-3100 controller used in electric vehicle charging stations.
Latest Phoenix Contact CHARX SEC-3100 vulnerabilities
- CVE-2026-7849: Phoenix Contact CHARX SEC command injection in system configurationcriticalCVSS 9.8
- CVE-2026-44108: Phoenix Contact CHARX SEC-3xxx firewall bypass during shutdowncriticalCVSS 9.8
- CVE-2026-44107: Phoenix Contact CHARX SEC charging controller unauthenticated reboot via Modbus TCPhighCVSS 7.5
- CVE-2026-44106: Phoenix Contact CHARX SEC-3xxx privilege escalation in init-scripthighCVSS 7.8
- CVE-2026-44105: Phoenix Contact CHARX SEC-3xxx credential exposure in log filesmediumCVSS 6.6
- CVE-2026-44104: Phoenix Contact CHARX SEC firmware update signature bypasscriticalCVSS 9.8
- CVE-2026-44103: Phoenix Contact CHARX SEC firmware integrity bypass in JupiCoremediumCVSS 5.3
- CVE-2026-44102: Phoenix Contact CHARX SEC race condition in firmware update cleanupmediumCVSS 5.3
- CVE-2026-44101: Phoenix Contact CHARX SEC-3xxx missing authentication in OCPP AgentcriticalCVSS 9.8
- CVE-2026-44100: Phoenix Contact CHARX SEC JupiCore missing authenticationcriticalCVSS 9.4
- CVE-2026-44099: Phoenix Contact CHARX SEC privilege escalation in system configurationhighCVSS 7.8
- CVE-2026-44098: Phoenix Contact CHARX SEC OS command injection in OCPP backendhighCVSS 8.6
- CVE-2026-44097: Phoenix Contact CHARX SEC unrestricted file upload in firmware REST endpointhighCVSS 7.1
- CVE-2026-44096: Phoenix Contact CHARX SEC-3xxx privilege escalation in udhcpchighCVSS 7.8
- CVE-2026-44095: Phoenix Contact CHARX SEC privilege escalation in network scripthighCVSS 7.8
- CVE-2026-44093: Phoenix Contact CHARX SEC-3xxx privilege escalation in init-scripthighCVSS 7.8
- CVE-2026-44092: Phoenix Contact CHARX SEC-3xxx CRLF injection in ModbusServercriticalCVSS 9.1
- CVE-2026-44091: Phoenix Contact CHARX SEC trust boundary violation in MQTT BrokercriticalCVSS 9.1
- CVE-2026-44090: Phoenix Contact CHARX SEC missing authentication in MQTT brokercriticalCVSS 9.8
- CVE-2026-41032: Phoenix Contact CHARX SEC-3xxx unauthenticated log downloadhighCVSS 7.5
Most severe Phoenix Contact CHARX SEC-3100 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-7849: Phoenix Contact CHARX SEC command injection in system configurationcriticalCVSS 9.8
- CVE-2026-44108: Phoenix Contact CHARX SEC-3xxx firewall bypass during shutdowncriticalCVSS 9.8
- CVE-2026-44104: Phoenix Contact CHARX SEC firmware update signature bypasscriticalCVSS 9.8
- CVE-2026-44101: Phoenix Contact CHARX SEC-3xxx missing authentication in OCPP AgentcriticalCVSS 9.8
- CVE-2026-44090: Phoenix Contact CHARX SEC missing authentication in MQTT brokercriticalCVSS 9.8
- CVE-2026-44100: Phoenix Contact CHARX SEC JupiCore missing authenticationcriticalCVSS 9.4
- CVE-2026-44092: Phoenix Contact CHARX SEC-3xxx CRLF injection in ModbusServercriticalCVSS 9.1
- CVE-2026-44091: Phoenix Contact CHARX SEC trust boundary violation in MQTT BrokercriticalCVSS 9.1
- CVE-2026-44098: Phoenix Contact CHARX SEC OS command injection in OCPP backendhighCVSS 8.6
- CVE-2026-44106: Phoenix Contact CHARX SEC-3xxx privilege escalation in init-scripthighCVSS 7.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 19 | 8 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/charx-sec-3100.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Phoenix Contact CHARX SEC-3100 vulnerabilities", https://junglewise.ai/threats/technologies/charx-sec-3100, 26 September 2026.