CVE-2025-25271

8.8

Phoenix Contact · CHARX SEC-3000, 3050, 3100, 3150

Unauthenticated adjacent attackers can configure a new OCPP backend in Phoenix Contact CHARX controllers due to insecure default resource initialization.

Executive summary

A critical vulnerability in Phoenix Contact CHARX controllers allows unauthenticated attackers on the local network to gain full control over the OCPP backend configuration.

Vulnerability

This vulnerability involves insecure default initialization of resources (CWE-1188), which permits an unauthenticated attacker present on the adjacent network to modify the Open Charge Point Protocol (OCPP) backend settings.

Business impact

The ability to reconfigure the OCPP backend poses a significant risk to the integrity and availability of electric vehicle charging infrastructure. An attacker could redirect traffic to a malicious server, leading to unauthorized data exfiltration, service disruption, or full system compromise. With a CVSS score of 8.8, this flaw represents a high risk to operational continuity and physical asset security.

Remediation

Immediate Action: Update all affected Phoenix Contact CHARX controllers to firmware version 1.7.3 or later as specified by the vendor advisory.

Proactive Monitoring: Monitor network traffic for unauthorized attempts to access the configuration interface or unexpected changes to OCPP backend destination URLs.

Compensating Controls: Restrict access to the management interfaces of charging controllers by implementing strict network segmentation and ensuring these devices are not exposed to untrusted adjacent network segments.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of potential unauthorized configuration changes, organizations utilizing affected Phoenix Contact CHARX controllers should prioritize firmware updates immediately. Verify that all devices are properly segmented from public or untrusted network segments to minimize the attack surface while the deployment of the vendor-provided patch is completed.

More Phoenix Contact CVEs

Sources

Originally found and disclosed by Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam), per the CVE Program record.