Description
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.
Published: 2026-07-30
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker can force the device to switch to a second RAUC firmware slot that contains insecure settings, including default credentials. Once the fallback occurs, the device’s SSH service permits login as the unprivileged user "user-app", allowing the attacker to remotely gain access to the system. This breach can lead to charging interruption and further compromise of device functions by an attacker who can execute commands with the privileges granted to that user.

Affected Systems

The vulnerability affects Phoenix Contact's CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 product series. No specific firmware versions are listed in the CVE report, so all firmware releases for these models should be considered potentially vulnerable until an update is applied.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity impact, but the EPSS score of less than 1% suggests the likelihood of exploitation is low at present. The vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to be remote unauthenticated, as the attacker only needs to trigger the fallback mechanism to obtain access using default credentials.

Generated by OpenCVE AI on August 3, 2026 at 11:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor-provided firmware update that removes default credentials and secures the RAUC slot configuration.
  • If an update is not immediately available, block SSH access to the insecure fallback slot using firewall rules or access‑control lists.
  • Replace the default credentials with strong, unique passwords and enforce a password policy to eliminate the insecure default credential weakness.
  • Consider disabling or restricting the automated fallback mechanism until the device is hardened or updated.

Generated by OpenCVE AI on August 3, 2026 at 11:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150
Vendors & Products Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.
Title Fallback to second RAUC slot with default credentials
First Time appeared Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
Weaknesses CWE-636
CPEs cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Charx Sec 3000 Charx Sec 3050 Charx Sec 3100 Charx Sec 3150
Phoenixcontact Charx Sec-3000 Charx Sec-3050 Charx Sec-3100 Charx Sec-3150
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-30T14:04:15.872Z

Reserved: 2026-05-05T10:48:08.226Z

Link: CVE-2026-44094

cve-icon Vulnrichment

Updated: 2026-07-30T14:03:20.696Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T07:16:57.403

Modified: 2026-07-30T15:16:33.033

Link: CVE-2026-44094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:03Z

Weaknesses
  • CWE-636

    Not Failing Securely ('Failing Open')