The CHARX OCPP Agent service on Phoenix Contact devices lacks authentication, allowing remote attackers to reconfigure backend connections and cause d...
Description
The CHARX OCPP Agent service on Phoenix Contact devices lacks authentication, allowing remote attackers to reconfigure backend connections and cause denial of service.
AI Analyst Comment
Remediation
Update Phoenix Contact CHARX SEC-3150 to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Phoenix Contact
PRODUCT: CHARX SEC-3150
AFFECTED_VERSIONS: 1.0.0 up to (excluding) 1.9.1 (also affects SEC-3100, SEC-3050, SEC-3000)
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The CHARX OCPP Agent service on Phoenix Contact devices lacks authentication, allowing remote attackers to reconfigure backend connections and cause denial of service.
Executive Summary:
A critical missing authentication vulnerability in the CHARX OCPP Agent allows unauthenticated attackers to reconfigure backend connections, leading to denial of service and potential data disclosure.
Vulnerability Details
CVE-ID: CVE-2026-44101
Affected Software: Phoenix Contact CHARX SEC-3150 (and SEC-3100, SEC-3050, SEC-3000)
Affected Versions: 1.0.0 up to (excluding) 1.9.1
Vulnerability: This is a missing authentication for critical function vulnerability (CWE-306). The OCPP Agent service fails to verify the identity of remote entities, granting an unauthenticated attacker the ability to alter backend connection settings.
Business Impact
Exploitation of this vulnerability enables attackers to disrupt charging station operations through denial of service or divert sensitive data by reconfiguring backend connections. Given the CVSS score of 9.8, the potential for service outages and information leakage is substantial. This risk is particularly high for operators of charging infrastructure who rely on secure connectivity to the backend management platform.
Remediation Plan
Immediate Action: Update the firmware of all affected CHARX SEC devices to version 1.9.1 or higher to enforce authentication for the OCPP Agent service.
Proactive Monitoring: Monitor the status of backend connections and review logs for unauthorized reconfiguration attempts or unexpected connection drops in the charging management system.
Compensating Controls: Restrict network access to the OCPP Agent service by implementing strict firewall rules and network segmentation, ensuring only verified management servers can communicate with the device.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 30, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The ability to remotely reconfigure backend connections is a critical flaw that could facilitate large-scale service disruption.
Analyst Recommendation
Operators must treat this vulnerability with high urgency to prevent potential operational downtime and data exposure. It is essential to apply the manufacturer-provided firmware updates and verify network security controls to protect the integrity of the backend management communications.