CVE-2025-25268
8.8Phoenix Contact · CHARX SEC Series
An unauthenticated adjacent attacker can modify device configurations via a specific API endpoint due to missing authentication checks.
Executive summary
A critical authentication bypass vulnerability in Phoenix Contact CHARX SEC controllers allows unauthenticated adjacent attackers to gain unauthorized read and write access to device configurations.
Vulnerability
This is a missing authentication for critical function vulnerability (CWE-306). An unauthenticated attacker positioned on the same local network segment can send crafted requests to a specific API endpoint, resulting in full read and write access to the device configuration.
Business impact
The potential for unauthorized configuration modification poses a severe risk to industrial operations, as attackers could alter operational parameters, disable safety features, or disrupt service. With a CVSS score of 8.8, this high-severity flaw threatens the integrity and availability of critical charging infrastructure. Successful exploitation could lead to significant operational downtime and potential physical safety risks depending on the deployment environment.
Remediation
Immediate Action: Update all affected Phoenix Contact CHARX SEC controller firmware to version 1.7.3 or later as specified in the vendor advisory.
Proactive Monitoring: Monitor network traffic for anomalous API calls originating from unauthorized or unexpected devices within the local network segment.
Compensating Controls: Implement network segmentation to isolate the charging controllers from untrusted devices and restrict access to the management API using firewall rules.
Exploitation status
Public Exploit Available: No — exploit_available (false)
Analyst recommendation
Given the high CVSS score and the potential for total loss of configuration control, organizations must prioritize patching these controllers immediately. If a patch cannot be applied instantly, network isolation is the most effective temporary control to prevent adjacent attackers from accessing the vulnerable API endpoint.
More Phoenix Contact CVEs
Sources
Originally found and disclosed by HT3 Labs, per the CVE Program record.