Charx Sec 3050 Phoenixcontact Charx Sec 3050

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Phoenixcontact Charx Sec 3050.

By the Year

In 2026 there have been 20 vulnerabilities in Phoenixcontact Charx Sec 3050 with an average score of 8.2 out of ten.

Year Vulnerabilities Average Score
2026 20 8.23

It may take a day or so for new Charx Sec 3050 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Phoenixcontact Charx Sec 3050 Security Vulnerabilities

Cmd Injection via Special Elements in System Config
CVE-2026-7849 9.8 - Critical - July 30, 2026

Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.

Command Injection

Premature Firewall Shutdown Exposes Services
CVE-2026-44108 9.8 - Critical - July 30, 2026

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.

Incorrect Behavior Order

CharxModbusServer Unauth Reboot via Modbus TCP DoS
CVE-2026-44107 7.5 - High - July 30, 2026

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.

Exposed Dangerous Method or Function

Local user credentials leaked via logs enabling SSH login as user-app
CVE-2026-44105 6.6 - Medium - July 30, 2026

The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.

Insertion of Sensitive Information into Log File

Priv Esc via User-App init-script
CVE-2026-44106 7.8 - High - July 30, 2026

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

Shell injection

Firmware Update in Charging Controller Lacks Signature (CVE-202644104)
CVE-2026-44104 9.8 - Critical - July 30, 2026

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.

Improper Verification of Cryptographic Signature

Unauthenticated Firmware Injection via JupiCore Service (CVE-2026-44103)
CVE-2026-44103 5.3 - Medium - July 30, 2026

An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.

Unrestricted File Upload

Unauthenticated OCPP Backend Remote Firmware Download Vulnerability
CVE-2026-44102 5.3 - Medium - July 30, 2026

An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.

Race Condition

Unauthenticated reconfig of CHARX OCPP Agent leads to DoS & Data Disclosure
CVE-2026-44101 9.8 - Critical - July 30, 2026

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.

Missing Authentication for Critical Function

Unauth Remote Reconfig Attack on CHARX JupiCore Charging Service
CVE-2026-44100 9.4 - Critical - July 30, 2026

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.

Missing Authentication for Critical Function

Local Privilege Escalation: User to Root via System Config
CVE-2026-44099 7.8 - High - July 30, 2026

A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

Shell injection

OS Cmd Injection in OCPP Backend via firewallbypass
CVE-2026-44098 8.6 - High - July 30, 2026

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.

Shell injection

IoT REST Firmware Upload Flaw: Arbitrary File Persistence
CVE-2026-44097 7.1 - High - July 30, 2026

A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.

Unrestricted File Upload

Privilege Escalation in udhcpc, local charx-web execs as root
CVE-2026-44096 7.8 - High - July 30, 2026

A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.

Shell injection

Priv Esc via Network Config Script on Linux
CVE-2026-44095 7.8 - High - July 30, 2026

A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

Shell injection

Firmware Partition Default Credentials Allow Unprivileged SSH Access
CVE-2026-44094 8.6 - High - July 30, 2026

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.

Failing Open

Local Priv. Escalation via init-script in systemd (CVE-2026-44093)
CVE-2026-44093 7.8 - High - July 30, 2026

A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

Shell injection

Unauthenticated Input Injection in ModbusServer via MQTT (CVE-2026-44092)
CVE-2026-44092 9.1 - Critical - July 30, 2026

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.

CRLF Injection

Unauthenticated ID Injection in MQTT Broker Creates Config Entry
CVE-2026-44091 9.1 - Critical - July 30, 2026

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.

Trust Boundary Violation

Unauthenticated Access to MQTT Broker (CVE-2026-44090)
CVE-2026-44090 9.8 - Critical - July 30, 2026

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.

Missing Authentication for Critical Function

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Phoenixcontact Charx Sec 3050 or by Phoenixcontact? Click the Watch button to subscribe.

subscribe