CVE-2026-44098

Phoenix Contact · CHARX SEC-3000, 3050, 3100, 3150

An OS command injection vulnerability in Phoenix Contact CHARX controllers allows unauthenticated remote attackers to execute arbitrary commands via the OCPP backend.

Executive summary

An OS command injection vulnerability in Phoenix Contact CHARX controllers allows unauthenticated remote attackers to execute arbitrary commands via the OCPP backend, posing a severe risk of system compromise.

Vulnerability

This is an OS command injection flaw (CWE-78) triggered when an unauthenticated remote attacker bypasses firewall restrictions to interact with the OCPP backend. Successful exploitation allows the execution of arbitrary commands with the privileges of the charx-oa user.

Business impact

Successful exploitation of this vulnerability could lead to unauthorized control over charging infrastructure, potentially causing operational disruption or unauthorized access to the underlying network. Given the CVSS score of 8.6, the risk is high: it enables attackers to manipulate controller functions without requiring valid user credentials.

Remediation

Immediate Action: Update all affected CHARX SEC controller units to firmware version 1.9.1 or higher immediately.

Proactive Monitoring: Monitor network traffic for anomalous OCPP communication patterns and audit system logs for unexpected command execution attempts.

Compensating Controls: Ensure that the OCPP backend is strictly isolated from public networks and implement firewall rules to prevent unauthorized access to the management interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this remote, unauthenticated vulnerability necessitates immediate patching. Organizations should prioritize updating their Phoenix Contact CHARX controllers to the latest firmware to eliminate the command injection vector and secure their industrial control environment.