CVE-2026-44108
Phoenix Contact · CHARX SEC-3150, SEC-3100, SEC-3050, SEC-3000
A script execution order flaw during system shutdown causes the firewall to terminate prematurely, exposing internal services to unauthenticated remote attackers.
Executive summary
A critical race condition in Phoenix Contact charging controllers exposes internal services to remote attackers during the system shutdown process.
Vulnerability
This is an incorrect behavior order (CWE-696) vulnerability. The firewall is shut down before other services, creating a temporary, exploitable window where internal network services are reachable by unauthenticated remote actors.
Business impact
With a CVSS score of 9.8, this vulnerability represents a high risk of unauthorized access to sensitive internal services. An attacker could leverage this window to gain a foothold in the controller, potentially leading to full system compromise or lateral movement within the operational network.
Remediation
Immediate Action: Update the affected Phoenix Contact CHARX controller firmware to version 1.9.1 or later to correct the service shutdown sequence.
Proactive Monitoring: Monitor network traffic for unusual connection attempts during periods of system maintenance or expected reboots.
Compensating Controls: Isolate the controllers within a restricted VLAN and utilize firewall rules to block unsolicited incoming traffic, even if the device internal firewall is temporarily disabled.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The vulnerability highlights a critical flaw in the system shutdown sequence that exposes internal services. Organizations must apply the vendor-provided firmware update to version 1.9.1 as soon as possible to ensure the firewall remains active until all services are safely terminated.