CVE-2025-25271
8.8Phoenix Contact · CHARX SEC-3000, 3050, 3100, 3150
Unauthenticated adjacent attackers can configure a new OCPP backend in Phoenix Contact CHARX controllers due to insecure default resource initialization.
Executive summary
A critical vulnerability in Phoenix Contact CHARX controllers allows unauthenticated attackers on the local network to gain full control over the OCPP backend configuration.
Vulnerability
This vulnerability involves insecure default initialization of resources (CWE-1188), which permits an unauthenticated attacker present on the adjacent network to modify the Open Charge Point Protocol (OCPP) backend settings.
Business impact
The ability to reconfigure the OCPP backend poses a significant risk to the integrity and availability of electric vehicle charging infrastructure. An attacker could redirect traffic to a malicious server, leading to unauthorized data exfiltration, service disruption, or full system compromise. With a CVSS score of 8.8, this flaw represents a high risk to operational continuity and physical asset security.
Remediation
Immediate Action: Update all affected Phoenix Contact CHARX controllers to firmware version 1.7.3 or later as specified by the vendor advisory.
Proactive Monitoring: Monitor network traffic for unauthorized attempts to access the configuration interface or unexpected changes to OCPP backend destination URLs.
Compensating Controls: Restrict access to the management interfaces of charging controllers by implementing strict network segmentation and ensuring these devices are not exposed to untrusted adjacent network segments.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the severity of potential unauthorized configuration changes, organizations utilizing affected Phoenix Contact CHARX controllers should prioritize firmware updates immediately. Verify that all devices are properly segmented from public or untrusted network segments to minimize the attack surface while the deployment of the vendor-provided patch is completed.
More Phoenix Contact CVEs
Sources
Originally found and disclosed by Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam), per the CVE Program record.