CVE-2026-44090

Phoenix Contact · CHARX SEC-3150

A missing authentication vulnerability in the Phoenix Contact CHARX SEC series allows unauthenticated remote attackers to access and potentially compromise the MQTT broker.

Executive summary

A critical missing authentication flaw in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by accessing the MQTT broker.

Vulnerability

This is a missing authentication for critical function vulnerability (CWE-306). The MQTT broker on the affected hardware lacks proper authentication, allowing an unauthenticated remote attacker to interact with the service if network access is permitted.

Business impact

The ability to access the MQTT broker allows an attacker to manipulate industrial control communications, leading to potential operational disruption or full device compromise. With a CVSS score of 9.8, this vulnerability poses a severe threat to operational technology environments. Unauthorized access may result in unauthorized control of physical processes, leading to safety risks and significant financial impact.

Remediation

Immediate Action: Update the firmware of all affected CHARX SEC devices to version 1.9.1 or higher to implement mandatory authentication for the MQTT broker.

Proactive Monitoring: Monitor network traffic for unauthorized access attempts directed at the MQTT port and review device logs for suspicious configuration changes or unexpected message publishing.

Compensating Controls: Ensure that all industrial control devices are isolated from the public internet via robust firewall rules and VPNs to restrict access to the MQTT broker to authorized internal sources only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant risk to industrial systems and must be addressed as a high priority. Administrators should ensure that firmware updates are applied to all impacted hardware and verify that network-level controls are in place to prevent unauthorized exposure of the MQTT broker.