Description
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.
Published: 2026-07-30
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local user named "charx-web" can exploit a flaw in the udhcpc service to run arbitrary commands as the root user, effectively breaking out of the restricted user context and gaining full system control. This vulnerability is a classic example of command injection, where unsanitized user input allows an attacker to inject malicious commands into a privileged process.

Affected Systems

The flaw appears in the Phoenix Contact CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. No specific firmware or software version numbers are provided, so any installation running the affected udhcpc component is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, while an EPSS score of less than 1% suggests the exploitation probability is low at present. The vulnerability is not listed as a known exploitable vulnerability in the CISA KEV catalog. The likely attack vector is a local system compromise where the attacker has administrative or root access to the device and can manipulate or restart udhcpc. Once the injection succeeds, the attacker can elevate privileges to root, compromising the entire system.

Generated by OpenCVE AI on August 3, 2026 at 11:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest firmware or patch that addresses the udhcpc command‑injection flaw.
  • Disable the udhcpc service if DHCP functionality is not required for the device’s operation.
  • If disabling is not feasible, re‑configure the system to prevent the "charx-web" user from running udhcpc or remove the user entirely.

Generated by OpenCVE AI on August 3, 2026 at 11:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150
Vendors & Products Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.
Title udhcpc Privilege Escalation
First Time appeared Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
Weaknesses CWE-78
CPEs cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Charx Sec 3000 Charx Sec 3050 Charx Sec 3100 Charx Sec 3150
Phoenixcontact Charx Sec-3000 Charx Sec-3050 Charx Sec-3100 Charx Sec-3150
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-31T22:45:06.024Z

Reserved: 2026-05-05T10:48:08.226Z

Link: CVE-2026-44096

cve-icon Vulnrichment

Updated: 2026-07-31T22:44:59.993Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T07:16:57.677

Modified: 2026-07-31T23:17:23.847

Link: CVE-2026-44096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')