CVE-2025-41699
8.8Phoenix Contact · CHARX SEC-3000/3050/3100/3150
A command injection vulnerability in Phoenix Contact CHARX controllers allows low-privileged authenticated remote attackers to execute arbitrary code as root via the web management interface.
Executive summary
Phoenix Contact CHARX controllers are vulnerable to a critical command injection flaw that allows low-privileged authenticated attackers to gain full root-level control over the system.
Vulnerability
This is a command injection vulnerability (CWE-94) triggered through the web-based management interface, where improper input validation allows an authenticated user with low privileges to inject and execute system commands with root privileges.
Business impact
A successful exploit results in a total loss of confidentiality, integrity, and availability, effectively granting the attacker full control over the affected hardware. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to unauthorized industrial process manipulation, permanent system compromise, or lateral movement within the operational technology network.
Remediation
Immediate Action: Update the firmware of all affected Phoenix Contact CHARX controllers to version 1.7.4 or later as specified in the vendor advisory.
Proactive Monitoring: Monitor network traffic to the web management interfaces for anomalous command patterns and review system logs for unauthorized configuration changes or unexpected process execution.
Compensating Controls: Restrict access to the web-based management interface to authorized management subnets and implement strict firewall rules to prevent unauthorized users from reaching the administration portal.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the severity of this vulnerability and the potential for complete system compromise, administrators must prioritize the firmware update to version 1.7.4. Restricting administrative access to the web interface remains a critical defensive measure until all devices have been successfully patched.
More Phoenix Contact CVEs
Sources
Originally found and disclosed by Ryo Kato of Panasonic Holdings Corporation, per the CVE Program record.