CVE-2025-24005
7.8Phoenix Contact · CHARX SEC-3000, 3050, 3100, 3150
A local privilege escalation vulnerability in Phoenix Contact CHARX controllers allows authenticated users to gain root access via improper input validation in a script accessible over SSH.
Executive summary
A local privilege escalation vulnerability in Phoenix Contact CHARX controllers allows authenticated users to gain root-level control, posing a significant risk to system integrity.
Vulnerability
This vulnerability involves improper input validation (CWE-20) within a script executed via SSH. An attacker who has already obtained a local user account can exploit this flaw to execute commands with root privileges.
Business impact
The ability for a local user to escalate to root status represents a total compromise of the affected controller. This could lead to unauthorized configuration changes, complete loss of confidentiality and integrity for system data, and potential disruption of critical infrastructure operations. Given the CVSS score of 7.8, this is classified as a High severity issue that requires immediate attention to prevent lateral movement or permanent system damage.
Remediation
Immediate Action: Update all affected Phoenix Contact CHARX controllers to firmware version 1.7.3 or later to remediate the vulnerable script.
Proactive Monitoring: Review SSH access logs for suspicious command patterns or unauthorized attempts to access administrative scripts.
Compensating Controls: Restrict SSH access to the controllers to only known, trusted administrative workstations and enforce the principle of least privilege for all local user accounts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing Phoenix Contact CHARX controllers must prioritize updating to version 1.7.3 immediately. Because this vulnerability facilitates a total compromise of the device from a low-privileged state, delaying the update increases the window of opportunity for an attacker to escalate privileges and maintain persistence on the device.
More Phoenix Contact CVEs
Sources
Originally found and disclosed by Jesson Soto Ventura, Matthew Waddell, per the CVE Program record.