Description
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.
Published: 2026-07-30
Score: 8.8 High
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an OS command injection flaw located in the OCPP Agent of the Phoenix Contact CHARX series, triggered via the charge_box_id parameter. An unauthenticated attacker who can reach the OCPP backend – for example, by bypassing network controls – can supply crafted input that is executed as the limited user charx-oa. The effect is the ability to run arbitrary commands on the device, which can disrupt charging operations or potentially be leveraged for further exploitation within the host environment. The weakness is a classic OS command injection (CWE‑78).

Affected Systems

Affected products are Phoenix Contact CHARX SEC‑3000, CHARX SEC‑3050, CHARX SEC‑3100, and CHARX SEC‑3150. No specific firmware or software version numbers are listed, so any system running these models is vulnerable unless a fix has been applied.

Risk and Exploitability

The CVSS score of 8.8 classifies this flaw as High severity, and the EPSS score of 1% indicates that while the likelihood of exploitation is low, it is not negligible. The vulnerability is not currently listed in CISA’s KEV catalog. An attacker can exploit it remotely without authentication by controlling the OCPP backend, typically after establishing a firewall bypass. Successful exploitation grants arbitrary command execution as the charx-oa user, which can stop charging and potentially be used as a foothold for further attacks within the local network.

Generated by OpenCVE AI on August 3, 2026 at 11:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or update to a fixed firmware version for all affected CharX devices
  • Restrict access to the OCPP backend by tightening firewall rules so that only trusted management IP addresses can reach the agent
  • Disable or isolate the OCPP interface if the device does not require remote management
  • Implement logging and monitoring of the OCPP agent for unexpected command execution or abnormal activity

Generated by OpenCVE AI on August 3, 2026 at 11:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150
Vendors & Products Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.
Title OS Command Injection in OCPP Agent via charge_box_id
First Time appeared Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
Weaknesses CWE-78
CPEs cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Charx Sec 3000 Charx Sec 3050 Charx Sec 3100 Charx Sec 3150
Phoenixcontact Charx Sec-3000 Charx Sec-3050 Charx Sec-3100 Charx Sec-3150
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-30T12:56:14.535Z

Reserved: 2026-05-05T10:48:08.226Z

Link: CVE-2026-44098

cve-icon Vulnrichment

Updated: 2026-07-30T12:56:11.422Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T07:16:57.950

Modified: 2026-07-30T14:31:21.447

Link: CVE-2026-44098

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')