Impact
A local user named "charx-web" can exploit a flaw in the udhcpc service to run arbitrary commands as the root user, effectively breaking out of the restricted user context and gaining full system control. This vulnerability is a classic example of command injection, where unsanitized user input allows an attacker to inject malicious commands into a privileged process.
Affected Systems
The flaw appears in the Phoenix Contact CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. No specific firmware or software version numbers are provided, so any installation running the affected udhcpc component is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, while an EPSS score of less than 1% suggests the exploitation probability is low at present. The vulnerability is not listed as a known exploitable vulnerability in the CISA KEV catalog. The likely attack vector is a local system compromise where the attacker has administrative or root access to the device and can manipulate or restart udhcpc. Once the injection succeeds, the attacker can elevate privileges to root, compromising the entire system.
OpenCVE Enrichment