CVE-2025-25269
8.4Phoenix Contact · CHARX SEC-3000, 3050, 3100, 3150
A command injection vulnerability in Phoenix Contact CHARX controllers allows unauthenticated local attackers to execute arbitrary commands with root privileges.
Executive summary
A critical command injection vulnerability in Phoenix Contact CHARX charging controllers allows unauthenticated local attackers to achieve full system compromise via root-level execution.
Vulnerability
The vulnerability is an OS command injection (CWE-78) flaw triggered by improper neutralization of special elements. An unauthenticated local attacker can inject malicious commands that the system subsequently executes with root-level privileges.
Business impact
The ability for an unauthenticated local user to gain root access poses a severe threat to operational integrity and system availability. Successful exploitation could lead to total control over the charging controller, potentially causing physical hardware damage, service disruption, or unauthorized manipulation of charging sessions. Given the CVSS score of 8.4, this vulnerability represents a high-severity risk that requires immediate attention to prevent privilege escalation within the industrial environment.
Remediation
Immediate Action: Update all affected Phoenix Contact CHARX controller firmware to version 1.7.3 or later as specified in the vendor advisory.
Proactive Monitoring: Monitor system logs for unauthorized authentication attempts or unexpected shell commands executed by non-privileged accounts.
Compensating Controls: Restrict physical access to the controller devices to authorized personnel only and disable unused local interfaces to minimize the attack surface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a significant risk to the security and stability of Phoenix Contact CHARX infrastructure. Administrators must prioritize the application of the vendor-provided firmware update to version 1.7.3 to neutralize the command injection vector. Until updates are deployed, ensure that physical access controls are strictly enforced to mitigate the risk of local exploitation.
More Phoenix Contact CVEs
Sources
Originally found and disclosed by HT3 Labs, per the CVE Program record.