CVE-2025-24003

8.2

Phoenix Contact · CHARX SEC Series

An unauthenticated remote attacker can trigger out-of-bounds writes in Phoenix Contact CHARX charging stations via MQTT messages, leading to integrity loss and potential denial-of-service.

Executive summary

An unauthenticated remote code execution vulnerability in Phoenix Contact CHARX charging stations poses a significant risk to operational integrity and service availability.

Vulnerability

The vulnerability is a classic buffer overflow (CWE-120) triggered by an unauthenticated remote attacker sending malformed MQTT messages, which causes an out-of-bounds write operation within the device firmware.

Business impact

The exploitation of this vulnerability results in a loss of integrity for the EichrechtAgent component and can lead to a denial-of-service condition for the charging station. With a CVSS score of 8.2 (High), the primary impact includes operational downtime and potential regulatory non-compliance regarding the German Calibration Law, which may necessitate costly manual interventions or service site visits.

Remediation

Immediate Action: Review the official advisory at certvde.com/en/advisories/VDE-2025-014 and apply vendor-provided firmware updates as soon as they become available for your specific model.

Proactive Monitoring: Monitor network traffic for anomalous MQTT message patterns or unauthorized connections targeting the charging station management ports.

Compensating Controls: Restrict network access to the MQTT broker and charging station interfaces to trusted internal segments only, utilizing firewall rules to block unauthorized external traffic.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the unauthenticated nature of this flaw and its ability to disrupt critical charging infrastructure, administrators must prioritize this vulnerability within their patch management lifecycle. Ensure that all affected CHARX SEC units are isolated from public-facing networks until verified security patches are deployed to prevent unauthorized remote manipulation.

More Phoenix Contact CVEs

Sources

Originally found and disclosed by Jesson Soto Ventura, Matthew Waddell, per the CVE Program record.