Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Plan PatchCVSS 9.8VDE-2026-008Jul 30, 2026
Phoenix Contact
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Multiple vulnerabilities in the firmware of CHARX SEC-3xxx EV charging controllers (SEC-3000, SEC-3050, SEC-3100, SEC-3150) allow remote attackers without authentication to compromise the devices and gain complete control. The flaws enable attackers to read sensitive data (confidentiality), modify charging operations or parameters (integrity), and disrupt or disable charging services (availability).
What this means
What could happen
An attacker with network access to a CHARX SEC charging controller could run commands remotely, gain full control of the device, and manipulate or disable EV charging operations at your facility.
Who's at risk
EV charging facility operators using Phoenix Contact CHARX SEC-3000, SEC-3050, or SEC-3150 charging controllers. This affects any organization with public or private EV charging infrastructure, including municipalities, utilities, transit agencies, and fleet operators.
How it could be exploited
An attacker sends a malicious network request to the charging controller. The controller processes the request without proper authentication or input validation, allowing the attacker to execute arbitrary code or bypass security controls. From there, the attacker can read sensitive data (like payment/authentication info), modify charging parameters, or halt all charging operations.
Prerequisites
- Network access to the charging controller (direct or via internal network)
- No authentication required to trigger the vulnerability
Remotely exploitableNo authentication requiredLow complexity attackHigh CVSS score (9.8)Affects safety-critical infrastructure (EV charging operations)
Exploitability
Some exploitation risk — EPSS score 1.4%
Affected products (3)
3 with fix
ProductAffected VersionsFix Status
CHARX SEC-3150≥ FW1.0.0, < FW1.9.1FW 1.9.1
CHARX SEC-3050≥ FW1.0.0, < FW1.9.1FW 1.9.1
CHARX SEC-3000≥ FW1.0.0, < FW1.9.1FW 1.9.1
Remediation & Mitigation
0/4
Do now
0/1WORKAROUNDIf unable to patch immediately, isolate affected charging controllers behind a firewall and restrict network access to only authorized management and vehicle communication interfaces
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
CHARX SEC-3000
HOTFIXUpdate CHARX SEC-3000, SEC-3050, and SEC-3150 charging controllers to firmware version 1.9.1 or later
Long-term hardening
0/2HARDENINGDisable any unnecessary or non-critical network services on the charging controllers
HARDENINGMonitor network traffic to the charging controllers for suspicious or unauthorized connection attempts
CVEs (20)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/fbe38726-7668-4567-8287-59b0382c6c61Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.