CVE-2026-7849

Phoenix Contact · CHARX SEC-3150, SEC-3100, SEC-3050, SEC-3000

An improper command neutralization vulnerability allows an unauthenticated remote attacker to execute arbitrary commands as root on the system.

Executive summary

A critical command injection vulnerability in Phoenix Contact charging controllers allows unauthenticated attackers to execute arbitrary code with root-level privileges.

Vulnerability

This is a command injection (CWE-77) flaw where input is not properly sanitized before being passed to a system command. An unauthenticated attacker can inject malicious commands, which the system then executes with root permissions.

Business impact

The CVSS score of 9.8 underscores the extreme severity of this flaw. Full root access grants an attacker the ability to manipulate charging parameters, install persistent malware, or disable safety mechanisms, which could have catastrophic impacts on both physical equipment and operational safety.

Remediation

Immediate Action: Update the affected Phoenix Contact CHARX controller firmware to version 1.9.1 or later to implement proper input sanitization.

Proactive Monitoring: Audit system logs for anomalous command execution patterns or unexpected changes to system configuration files.

Compensating Controls: Implement strict network ingress filtering to ensure that only authorized traffic can reach the configuration interfaces of the charging controllers.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Command injection vulnerabilities are high-priority targets for attackers. It is imperative that all affected CHARX controllers are updated to version 1.9.1 immediately to close this vector and prevent unauthorized root access to the underlying operating system.