CVE-2025-24006
7.8Phoenix Contact · CHARX SEC
An improper privilege management vulnerability in Phoenix Contact CHARX SEC devices allows low privileged local attackers to escalate privileges to root via insecure SSH permissions.
Executive summary
A local privilege escalation vulnerability in Phoenix Contact CHARX SEC charging controllers allows attackers with low-level access to gain full root control over the device.
Vulnerability
This vulnerability, categorized as CWE-269 (Improper Privilege Management), occurs due to insecure permissions configured within the SSH service. The flaw allows an already authenticated low privileged user to bypass standard access controls and execute commands with root-level privileges.
Business impact
The ability for a low privileged attacker to escalate to root privileges poses a severe threat to operational integrity. A successful exploit could lead to complete system compromise, unauthorized modification of charging controller logic, and potential disruption of critical infrastructure services. With a CVSS score of 7.8, this high-severity flaw necessitates prompt attention to prevent unauthorized administrative control.
Remediation
Immediate Action: Update all affected Phoenix Contact CHARX SEC devices to firmware version 1.7.3 or later as specified in the VDE-2025-014 security advisory.
Proactive Monitoring: Audit system logs for unauthorized SSH access attempts or unusual command execution patterns by non-root service accounts.
Compensating Controls: Restrict physical and network access to the SSH management interface to only authorized administration workstations to limit the exposure of the vulnerable service.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for full system takeover, organizations utilizing Phoenix Contact CHARX SEC controllers should prioritize the application of the 1.7.3 firmware update. If immediate patching is not feasible, ensure that network-level access to the device management interfaces is strictly segmented and monitored to mitigate the risk of local escalation by unauthorized actors.
More Phoenix Contact CVEs
Sources
Originally found and disclosed by Jesson Soto Ventura, Matthew Waddell, per the CVE Program record.