CVE-2026-44090
Phoenix Contact · CHARX SEC-3150
A missing authentication vulnerability in the Phoenix Contact CHARX SEC series allows unauthenticated remote attackers to access and potentially compromise the MQTT broker.
Executive summary
A critical missing authentication flaw in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by accessing the MQTT broker.
Vulnerability
This is a missing authentication for critical function vulnerability (CWE-306). The MQTT broker on the affected hardware lacks proper authentication, allowing an unauthenticated remote attacker to interact with the service if network access is permitted.
Business impact
The ability to access the MQTT broker allows an attacker to manipulate industrial control communications, leading to potential operational disruption or full device compromise. With a CVSS score of 9.8, this vulnerability poses a severe threat to operational technology environments. Unauthorized access may result in unauthorized control of physical processes, leading to safety risks and significant financial impact.
Remediation
Immediate Action: Update the firmware of all affected CHARX SEC devices to version 1.9.1 or higher to implement mandatory authentication for the MQTT broker.
Proactive Monitoring: Monitor network traffic for unauthorized access attempts directed at the MQTT port and review device logs for suspicious configuration changes or unexpected message publishing.
Compensating Controls: Ensure that all industrial control devices are isolated from the public internet via robust firewall rules and VPNs to restrict access to the MQTT broker to authorized internal sources only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a significant risk to industrial systems and must be addressed as a high priority. Administrators should ensure that firmware updates are applied to all impacted hardware and verify that network-level controls are in place to prevent unauthorized exposure of the MQTT broker.