CVE-2026-44108

Phoenix Contact · CHARX SEC-3150, SEC-3100, SEC-3050, SEC-3000

A script execution order flaw during system shutdown causes the firewall to terminate prematurely, exposing internal services to unauthenticated remote attackers.

Executive summary

A critical race condition in Phoenix Contact charging controllers exposes internal services to remote attackers during the system shutdown process.

Vulnerability

This is an incorrect behavior order (CWE-696) vulnerability. The firewall is shut down before other services, creating a temporary, exploitable window where internal network services are reachable by unauthenticated remote actors.

Business impact

With a CVSS score of 9.8, this vulnerability represents a high risk of unauthorized access to sensitive internal services. An attacker could leverage this window to gain a foothold in the controller, potentially leading to full system compromise or lateral movement within the operational network.

Remediation

Immediate Action: Update the affected Phoenix Contact CHARX controller firmware to version 1.9.1 or later to correct the service shutdown sequence.

Proactive Monitoring: Monitor network traffic for unusual connection attempts during periods of system maintenance or expected reboots.

Compensating Controls: Isolate the controllers within a restricted VLAN and utilize firewall rules to block unsolicited incoming traffic, even if the device internal firewall is temporarily disabled.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The vulnerability highlights a critical flaw in the system shutdown sequence that exposes internal services. Organizations must apply the vendor-provided firmware update to version 1.9.1 as soon as possible to ensure the firewall remains active until all services are safely terminated.