<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>CHARX SEC-3050 (&lt; 1.9.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/charx-sec-3050--1.9.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 30 Jul 2026 08:12:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/charx-sec-3050--1.9.1/feed.xml" rel="self" type="application/rss+xml"/><item><title>Unauthenticated Remote Access to Phoenix Contact CHARX SEC MQTT Broker</title><link>https://feed.craftedsignal.io/briefs/2026-07-mqtt-auth-bypass/</link><pubDate>Thu, 30 Jul 2026 08:12:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-mqtt-auth-bypass/</guid><description>A critical vulnerability (CVE-2026-44090) in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by bypassing authentication on the MQTT broker.</description><content:encoded><![CDATA[<p>Phoenix Contact has disclosed a critical security vulnerability, CVE-2026-44090, affecting its CHARX SEC series controllers. The vulnerability stems from a missing authentication mechanism within the onboard MQTT broker, which handles message queuing and device communication. Because the broker lacks required authentication, an unauthenticated remote attacker with network reach to the device can interface directly with the broker. While these devices are typically intended to be protected by external firewalls, the absence of internal authentication means that any misconfiguration or firewall bypass permits full unauthorized command execution and device compromise. The vulnerability affects firmware versions prior to 1.9.1. Organizations utilizing these controllers in industrial or EV charging infrastructure should prioritize upgrading to firmware version 1.9.1 or later and verify that network exposure is strictly limited.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs network reconnaissance to identify exposed CHARX SEC controllers (e.g., scanning for open ports associated with MQTT).</li>
<li>Attacker bypasses perimeter firewall protections if the device is misconfigured or exposed via port forwarding.</li>
<li>Attacker establishes a TCP connection to the MQTT broker port (typically 1883 or 8883) on the target controller.</li>
<li>Attacker transmits unauthenticated MQTT control packets to the broker.</li>
<li>The broker, lacking authentication, accepts the connection and processes the malicious commands.</li>
<li>Attacker leverages MQTT topics to send commands to internal device functions or application-layer services.</li>
<li>The device executes the commands with high-level privileges, leading to a full system compromise.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-44090 results in full compromise of the CHARX SEC controller. This can lead to unauthorized control over industrial or charging processes, loss of operational integrity, and potential lateral movement into the wider industrial control network. The impact is assessed as high across confidentiality, integrity, and availability (CVSS 9.8).</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all affected Phoenix Contact CHARX SEC controllers to firmware version 1.9.1 or later immediately.</li>
<li>Audit firewall configurations to ensure that the MQTT broker ports are not exposed to untrusted networks.</li>
<li>Implement network segmentation to ensure that only authorized services can reach the MQTT broker interface on industrial controllers.</li>
<li>Deploy network-based intrusion detection signatures to identify unauthorized MQTT traffic patterns targeting the specific CHARX SEC devices in the environment.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>industrial-control-systems</category><category>mqtt</category><category>cve-2026-44091</category><category>ics</category><category>cve</category><category>injection</category><category>authentication-bypass</category><category>cve-2026-44100</category><category>cve-2026-44101</category><category>ocpp</category><category>phoenix-contact</category><category>ot-security</category><category>vulnerability</category><category>firmware</category><category>embedded-systems</category><category>privilege-escalation</category><category>industrial-control-system</category><category>cve-2026-44093</category><category>file-upload</category><category>denial-of-service</category><category>modbus</category><category>cve-2026-44107</category></item></channel></rss>