CVE-2026-44100

Phoenix Contact · CHARX SEC-3150

The CHARX JupiCore service in various Phoenix Contact CHARX SEC controllers contains a missing authentication vulnerability, allowing unauthenticated remote attackers to reconfigure charging points.

Executive summary

A critical authentication bypass in Phoenix Contact CHARX controllers allows unauthenticated remote attackers to manipulate charging point configurations, potentially causing service disruption.

Vulnerability

The CHARX JupiCore service fails to enforce proper authentication for critical functions. This allows an unauthenticated remote attacker to perform unauthorized reconfigurations, leading to the disclosure of sensitive UIDs, denial-of-service conditions, and file tampering.

Business impact

The ability to manipulate industrial charging infrastructure remotely carries significant operational risk. With a CVSS score of 9.4, the vulnerability enables attackers to disrupt service availability or potentially cause physical damage to connected assets through unauthorized configuration changes, leading to severe reputational and financial impacts.

Remediation

Immediate Action: Update all affected CHARX SEC controller units to firmware version 1.9.1 or later as specified by the vendor advisory.

Proactive Monitoring: Review system logs for unauthorized configuration change events and monitor for abnormal communication patterns targeting the JupiCore service.

Compensating Controls: Deploy network segmentation to isolate industrial control systems from public-facing networks and utilize industrial firewalls to restrict access to the affected service.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing affected Phoenix Contact hardware must prioritize the firmware update to version 1.9.1. Given the potential for operational disruption and unauthorized access, ensuring all controllers are updated is essential to maintaining the integrity of the charging infrastructure.