CVE-2026-44094
Phoenix Contact · CHARX SEC-3150, SEC-3100, SEC-3050, SEC-3000
The Phoenix Contact CHARX series is vulnerable to a fail-open condition, allowing attackers to force a fallback to a firmware partition containing default credentials.
Executive summary
A failure to secure the firmware partition fallback process in Phoenix Contact CHARX devices allows unauthenticated attackers to gain unauthorized access via default credentials.
Vulnerability
The devices exhibit a fail-open behavior (CWE-636) where an unauthenticated remote attacker can force a transition to a legacy or secondary firmware partition. This partition contains insecure configurations, specifically the use of default credentials, which can be exploited for unauthorized access.
Business impact
The CVSS score of 8.6 indicates a high risk of unauthorized access and potential loss of availability. By forcing the system to a less secure state, attackers can bypass current authentication mechanisms, leading to complete device control, data exfiltration, or the disabling of charging operations.
Remediation
Immediate Action: Update the affected CHARX devices to firmware version 1.9.1 or later.
Proactive Monitoring: Monitor device logs for unexpected partition changes or attempts to authenticate with default credentials.
Compensating Controls: Ensure that management interfaces are isolated from public networks and that all default passwords are changed on all accessible partitions.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The reliance on default credentials in legacy firmware partitions presents a significant security gap. Administrators must prioritize the upgrade to version 1.9.1 to ensure that the device does not fall back to an insecure state, thereby mitigating the risk of unauthorized administrative access.