{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/charx-sec-3100/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-44095"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CHARX SEC-3000","CHARX SEC-3050","CHARX SEC-3100","CHARX SEC-3150"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","industrial-control-systems","cve","command-injection"],"_cs_type":"advisory","_cs_vendors":["Phoenix Contact"],"content_html":"\u003cp\u003ePhoenix Contact has disclosed a critical security vulnerability, tracked as CVE-2026-44095, affecting its CHARX SEC series of charging controllers. The vulnerability stems from improper neutralization of special elements used in OS commands (CWE-78) within a script responsible for network configuration. A low-privileged local user can leverage this flaw to escape restricted execution environments and inject arbitrary commands that execute with root-level privileges. This vulnerability affects CHARX SEC-3000, 3050, 3100, and 3150 models running firmware versions earlier than 1.9.1. Successful exploitation results in complete system compromise, enabling attackers to gain full control over the charging controller hardware, potentially impacting industrial control and power management functions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains low-privileged local access to the CHARX SEC charging controller via a standard user account or compromised management interface.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the specific network configuration script that processes user-supplied input without proper validation.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious command string containing shell metacharacters designed to break out of the intended script parameters.\u003c/li\u003e\n\u003cli\u003eAttacker executes the malicious string via the vulnerable script interface.\u003c/li\u003e\n\u003cli\u003eThe script fails to sanitize the input, passing the concatenated command to the underlying system shell.\u003c/li\u003e\n\u003cli\u003eThe shell executes the injected payload with root privileges (UID 0), granting the attacker full administrative access to the device.\u003c/li\u003e\n\u003cli\u003eAttacker establishes persistence or performs unauthorized actions such as disabling security controls, modifying device traffic, or exfiltrating sensitive operational data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-44095 grants an attacker root access to the affected CHARX charging controllers. This enables full control over the device, which may lead to service disruption, manipulation of charging parameters, or unauthorized access to the broader industrial network environment. Organizations using these devices in critical infrastructure or public EV charging deployments are at risk of localized physical and digital impact if the controllers are compromised at scale.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all affected Phoenix Contact CHARX SEC-3000, 3050, 3100, and 3150 controllers to firmware version 1.9.1 or higher to remediate CVE-2026-44095.\u003c/li\u003e\n\u003cli\u003eRestrict physical and logical access to the management console of the charging controllers to prevent unauthorized local user sessions.\u003c/li\u003e\n\u003cli\u003eMonitor local system logs on charging controllers for unexpected process execution by non-administrative user accounts.\u003c/li\u003e\n\u003cli\u003eAudit custom scripts or configuration files on the device for improper handling of shell input parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T08:14:01Z","date_published":"2026-07-30T08:13:36Z","id":"https://feed.craftedsignal.io/briefs/2026-07-phoenix-charx-privesc/","summary":"A local OS command injection vulnerability (CVE-2026-44095) in Phoenix Contact CHARX charging controllers allows low-privileged users to execute arbitrary commands as root.","title":"Privilege Escalation Vulnerability in Phoenix Contact CHARX Controllers","url":"https://feed.craftedsignal.io/briefs/2026-07-phoenix-charx-privesc/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-44090"},{"cvss":7.8,"id":"CVE-2026-44099"},{"cvss":9.1,"id":"CVE-2026-44091"},{"cvss":9.1,"id":"CVE-2026-44092"},{"cvss":9.4,"id":"CVE-2026-44100"},{"cvss":9.8,"id":"CVE-2026-44101"},{"cvss":9.8,"id":"CVE-2026-44104"},{"cvss":9.8,"id":"CVE-2026-44108"},{"cvss":7.8,"id":"CVE-2026-44093"},{"cvss":8.6,"id":"CVE-2026-44094"},{"cvss":7.8,"id":"CVE-2026-44096"},{"cvss":7.1,"id":"CVE-2026-44097"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CHARX SEC-3150","CHARX SEC-3100","CHARX SEC-3050","CHARX SEC-3000","CHARX SEC-3150 (\u003c 1.9.1)","CHARX SEC-3100 (\u003c 1.9.1)","CHARX SEC-3050 (\u003c 1.9.1)","CHARX SEC-3000 (\u003c 1.9.1)"],"_cs_severities":["critical"],"_cs_tags":["industrial-control-systems","mqtt","cve-2026-44091","ics","cve","injection","authentication-bypass","cve-2026-44100","cve-2026-44101","ocpp","phoenix-contact","ot-security","vulnerability","firmware","embedded-systems","privilege-escalation","industrial-control-system","cve-2026-44093","file-upload","denial-of-service","modbus","cve-2026-44107"],"_cs_type":"advisory","_cs_vendors":["Phoenix Contact"],"content_html":"\u003cp\u003ePhoenix Contact has disclosed a critical security vulnerability, CVE-2026-44090, affecting its CHARX SEC series controllers. The vulnerability stems from a missing authentication mechanism within the onboard MQTT broker, which handles message queuing and device communication. Because the broker lacks required authentication, an unauthenticated remote attacker with network reach to the device can interface directly with the broker. While these devices are typically intended to be protected by external firewalls, the absence of internal authentication means that any misconfiguration or firewall bypass permits full unauthorized command execution and device compromise. The vulnerability affects firmware versions prior to 1.9.1. Organizations utilizing these controllers in industrial or EV charging infrastructure should prioritize upgrading to firmware version 1.9.1 or later and verify that network exposure is strictly limited.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify exposed CHARX SEC controllers (e.g., scanning for open ports associated with MQTT).\u003c/li\u003e\n\u003cli\u003eAttacker bypasses perimeter firewall protections if the device is misconfigured or exposed via port forwarding.\u003c/li\u003e\n\u003cli\u003eAttacker establishes a TCP connection to the MQTT broker port (typically 1883 or 8883) on the target controller.\u003c/li\u003e\n\u003cli\u003eAttacker transmits unauthenticated MQTT control packets to the broker.\u003c/li\u003e\n\u003cli\u003eThe broker, lacking authentication, accepts the connection and processes the malicious commands.\u003c/li\u003e\n\u003cli\u003eAttacker leverages MQTT topics to send commands to internal device functions or application-layer services.\u003c/li\u003e\n\u003cli\u003eThe device executes the commands with high-level privileges, leading to a full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-44090 results in full compromise of the CHARX SEC controller. This can lead to unauthorized control over industrial or charging processes, loss of operational integrity, and potential lateral movement into the wider industrial control network. The impact is assessed as high across confidentiality, integrity, and availability (CVSS 9.8).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all affected Phoenix Contact CHARX SEC controllers to firmware version 1.9.1 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit firewall configurations to ensure that the MQTT broker ports are not exposed to untrusted networks.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to ensure that only authorized services can reach the MQTT broker interface on industrial controllers.\u003c/li\u003e\n\u003cli\u003eDeploy network-based intrusion detection signatures to identify unauthorized MQTT traffic patterns targeting the specific CHARX SEC devices in the environment.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-30T08:14:13Z","date_published":"2026-07-30T08:12:15Z","id":"https://feed.craftedsignal.io/briefs/2026-07-mqtt-auth-bypass/","summary":"A critical vulnerability (CVE-2026-44090) in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by bypassing authentication on the MQTT broker.","title":"Unauthenticated Remote Access to Phoenix Contact CHARX SEC MQTT Broker","url":"https://feed.craftedsignal.io/briefs/2026-07-mqtt-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - CHARX SEC-3100","version":"https://jsonfeed.org/version/1.1"}