CVE-2026-44104

Phoenix Contact · CHARX SEC-3150, SEC-3100, SEC-3050, SEC-3000

The firmware update process for Phoenix Contact charging controllers lacks cryptographic signature verification, allowing unauthenticated remote attackers to install malicious firmware.

Executive summary

A critical vulnerability in Phoenix Contact charging controllers allows unauthenticated attackers to achieve full system compromise by installing unauthorized firmware.

Vulnerability

This is an improper verification of cryptographic signature (CWE-347) flaw. Because the system only checks the CRC32 checksum of firmware updates, an unauthenticated attacker can bypass integrity checks to execute arbitrary code with system-level privileges.

Business impact

The CVSS score of 9.8 reflects the high potential for total system compromise, which poses a severe risk to operational technology environments. Successful exploitation could lead to full control over charging infrastructure, resulting in significant safety hazards, equipment damage, and prolonged service downtime.

Remediation

Immediate Action: Update the affected Phoenix Contact CHARX controller firmware to version 1.9.1 or later immediately.

Proactive Monitoring: Review device logs for unauthorized firmware update requests or unexpected system reboots that may indicate an attempted update.

Compensating Controls: Restrict network access to the management interfaces of these controllers to trusted internal management segments only, effectively preventing remote unauthenticated access.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity of this vulnerability, immediate patching is required to prevent unauthorized firmware modification. Administrators must prioritize updating all affected charging controllers to version 1.9.1 to ensure the integrity of the boot and update process.