24h | 7d | 30d

Overview

  • Phoenix Contact
  • CHARX SEC-3150

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.24%

KEV

Description

An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.

Statistics

  • 1 Post

Last activity: 17 hours ago

Fediverse

Profile picture fallback

VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Phoenix Contact
  • CHARX SEC-3150

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.46%

KEV

Description

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.

Statistics

  • 1 Post

Last activity: 17 hours ago

Fediverse

Profile picture fallback

VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Phoenix Contact
  • CHARX SEC-3150

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.31%

KEV

Description

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.

Statistics

  • 1 Post

Last activity: 17 hours ago

Fediverse

Profile picture fallback

VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Phoenix Contact
  • CHARX SEC-3150

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.28%

KEV

Description

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.

Statistics

  • 1 Post

Last activity: 17 hours ago

Fediverse

Profile picture fallback

VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Phoenix Contact
  • CHARX SEC-3150

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.24%

KEV

Description

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.

Statistics

  • 1 Post

Last activity: 17 hours ago

Fediverse

Profile picture fallback

VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Phoenix Contact
  • CHARX SEC-3150

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.21%

KEV

Description

An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.

Statistics

  • 1 Post

Last activity: 17 hours ago

Fediverse

Profile picture fallback

VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Phoenix Contact
  • CHARX SEC-3150

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v4.0
HIGH (8.5)
EPSS
0.23%

KEV

Description

A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.

Statistics

  • 1 Post

Last activity: 17 hours ago

Fediverse

Profile picture fallback

VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Phoenix Contact
  • CHARX SEC-3150

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.33%

KEV

Description

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.

Statistics

  • 1 Post

Last activity: 17 hours ago

Fediverse

Profile picture fallback

VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Phoenix Contact
  • CHARX SEC-3150

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
1.37%

KEV

Description

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.

Statistics

  • 1 Post

Last activity: 17 hours ago

Fediverse

Profile picture fallback

VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Phoenix Contact
  • CHARX SEC-3150

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.38%

KEV

Description

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.

Statistics

  • 1 Post

Last activity: 17 hours ago

Fediverse

Profile picture fallback

VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

  • 0
  • 0
  • 0
  • 17h ago
Showing 71 to 80 of 80 CVEs