TL;DR: Phoenix Contact CHARX vulnerabilities now number 20 across the SEC-3xxx EV charging controllers. Several rate critical, and the worst let an unauthenticated attacker gain root access remotely. Firmware 1.9.1 fixes every reported flaw.
- Total: 20 CVEs
- Severity: 8 Critical · 9 High · 3 Medium
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-7849
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-7849 | 9.8 | Command Injection in SCM (idledisconnect parameter) | 1.9.1 | Not exploited |
| CVE-2026-44090 | 9.8 | Missing authentication for MQTT Broker | 1.9.1 | Not exploited |
| CVE-2026-44101 | 9.8 | OCPP reconfiguration | 1.9.1 | Not exploited |
| CVE-2026-44104 | 9.8 | ControllerAgent does not perform validation of firmware | 1.9.1 | Not exploited |
| CVE-2026-44108 | 9.8 | Firewall bypass during shutdown | 1.9.1 | Not exploited |
| CVE-2026-44100 | 9.4 | JupiCore charging point reconfiguration without auth | 1.9.1 | Not exploited |
| CVE-2026-44091 | 9.1 | Creation of a new configuration by posting a malicious ID to MQTT | 1.9.1 | Not exploited |
| CVE-2026-44092 | 9.1 | Missing input validation / stripping of CRLF characters in SystemConfigManager | 1.9.1 | Not exploited |
Why these flaws matter
CHARX SEC controllers run electric vehicle charging in industrial and semi-public settings. The advisory warns that the bugs can cause a total loss of confidentiality, integrity, and availability. In plain terms, an attacker could seize full control of a charging station.
Moreover, many controllers connect to operator backends that reach past the local network. As a result, the exposure surface can extend well beyond one site.
How the attacks work
The flaws span several components. For instance, CVE-2026-44090 exposes the MQTT broker with no authentication. CVE-2026-7849 lets a remote attacker inject a command that then runs as root. CVE-2026-44108 shuts down the firewall too early during a reboot, which briefly exposes internal services.
Other bugs include firmware that skips signature checks and init scripts that permit local privilege escalation. Together, these Phoenix Contact CHARX vulnerabilities open many paths to root.
This report keeps the mechanics high level. It shares no exploit code and no step-by-step instructions.
Exploitation status
No confirmed in-the-wild attacks exist so far. Independent trackers also report no public proof-of-concept at the time of analysis. Even so, the critical ratings make fast patching the smart move.
Affected versions
The bugs hit the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. Every firmware release from 1.0.0 up to 1.9.1 is vulnerable, according to the vendor. Four product references carry the affected firmware, per INCIBE.
Patch and mitigation
Phoenix Contact recommends firmware 1.9.1, which addresses these vulnerabilities. The vendor said the update would ship no later than August 12, 2026, so watch the product download page. Until then, keep each EV charging controller in a closed network behind a firewall.
For the full technical breakdown, see the CERT@VDE advisory for VDE-2026-008. Segmenting charging networks from corporate and public traffic cuts the risk further. These Phoenix Contact CHARX vulnerabilities deserve prompt attention from every operator.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.