Description
A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Published: 2026-07-30
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A privilege escalation vulnerability exists in the network configuration script of Phoenix Contact devices. The script improperly handles user input, allowing a low‑privileged local user to inject arbitrary operating system commands. As a result, the attacker can execute commands with root privileges, achieving full system compromise. The flaw aligns with CWE‑78, an OS command injection weakness.

Affected Systems

The vulnerability affects Phoenix Contact CHARX SEC‑3000, CHARX SEC‑3050, CHARX SEC‑3100, and CHARX SEC‑3150 models. No specific firmware or software version information is provided, so all current revisions of these devices are potentially impacted.

Risk and Exploitability

The vulnerability carries a high severity CVSS score of 8.5, but the EPSS score is less than 1%, indicating a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. Likely exploitation requires that an attacker gains a local user account with limited privileges and uses the vulnerable network script, which then runs with root privileges. Because the attack is local, the risk is confined to environments where local accounts exist and can be compromised.

Generated by OpenCVE AI on August 3, 2026 at 11:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware upgrade or security patch released by Phoenix Contact that fixes the command injection in the network configuration script.
  • Restrict the permissions of the network configuration script so that only privileged users can execute it, or disable the script for local user access if the feature is not required.
  • Enable logging and monitoring of command execution and audit local accounts to detect unauthorized usage, and enforce the principle of least privilege for all local user accounts.

Generated by OpenCVE AI on August 3, 2026 at 11:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150
Vendors & Products Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Title Local Privilege Escalation via Network scripts
First Time appeared Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
Weaknesses CWE-78
CPEs cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Charx Sec 3000 Charx Sec 3050 Charx Sec 3100 Charx Sec 3150
Phoenixcontact Charx Sec-3000 Charx Sec-3050 Charx Sec-3100 Charx Sec-3150
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-30T12:32:56.327Z

Reserved: 2026-05-05T10:48:08.226Z

Link: CVE-2026-44095

cve-icon Vulnrichment

Updated: 2026-07-30T12:32:46.099Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T07:16:57.540

Modified: 2026-07-30T14:31:21.447

Link: CVE-2026-44095

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')