{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/charx-sec-3000-1.0.0-1.9.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-7849"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CHARX SEC-3150 (1.0.0-1.9.0)","CHARX SEC-3100 (1.0.0-1.9.0)","CHARX SEC-3050 (1.0.0-1.9.0)","CHARX SEC-3000 (1.0.0-1.9.0)"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-7849","command-injection","industrial-control-system"],"_cs_type":"advisory","_cs_vendors":["Phoenix Contact"],"content_html":"\u003cp\u003eCVE-2026-7849 is a critical command injection vulnerability impacting multiple models of the Phoenix Contact CHARX SEC series controllers, including versions 1.0.0 through 1.9.0. The vulnerability originates from improper neutralization of special elements within system configuration inputs. An unauthenticated, remote attacker can leverage this flaw to inject arbitrary commands, which are subsequently executed with root-level privileges on the target device. This vulnerability presents a high risk to industrial control environments, as successful exploitation results in full system compromise. Users are advised to upgrade affected CHARX SEC-3000, 3050, 3100, and 3150 controllers to firmware version 1.9.1 or later.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a network-accessible CHARX SEC controller interface.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload containing shell metacharacters designed to bypass input validation.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP request or relevant management protocol message to the device configuration endpoint.\u003c/li\u003e\n\u003cli\u003eThe vulnerable service fails to properly sanitize the input, passing the malicious string to the system shell.\u003c/li\u003e\n\u003cli\u003eThe command is executed by the system process running with root privileges.\u003c/li\u003e\n\u003cli\u003eThe attacker gains persistent remote code execution, enabling further exploitation, lateral movement, or disruption of industrial operations.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-7849 allows an unauthenticated attacker to achieve full administrative control (root) over the affected industrial controllers. This can lead to the manipulation of charging infrastructure processes, data exfiltration, or complete loss of control over the affected hardware. Given the role of CHARX SEC controllers in energy management, the impact of compromise includes operational downtime and potential safety risks in connected systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all affected CHARX SEC controller units to firmware version 1.9.1 or higher immediately, as specified in the CERT VDE advisory VDE-2026-008.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the management interfaces of CHARX SEC controllers to trusted IP segments using hardware firewalls or VLAN isolation.\u003c/li\u003e\n\u003cli\u003eAudit network logs for anomalous HTTP requests or management traffic directed at controller configuration endpoints that include shell metacharacters such as semicolon, pipe, or ampersand symbols.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T08:13:12Z","date_published":"2026-07-30T08:13:12Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-7849/","summary":"An unauthenticated remote command injection vulnerability in Phoenix Contact CHARX SEC controllers allows attackers to execute arbitrary code as root via malformed system configuration inputs.","title":"Command Injection in Phoenix Contact CHARX SEC Controllers","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-7849/"}],"language":"en","title":"CraftedSignal Threat Feed - CHARX SEC-3000 (1.0.0-1.9.0)","version":"https://jsonfeed.org/version/1.1"}