Impact
This vulnerability is an OS command injection flaw located in the OCPP Agent of the Phoenix Contact CHARX series, triggered via the charge_box_id parameter. An unauthenticated attacker who can reach the OCPP backend – for example, by bypassing network controls – can supply crafted input that is executed as the limited user charx-oa. The effect is the ability to run arbitrary commands on the device, which can disrupt charging operations or potentially be leveraged for further exploitation within the host environment. The weakness is a classic OS command injection (CWE‑78).
Affected Systems
Affected products are Phoenix Contact CHARX SEC‑3000, CHARX SEC‑3050, CHARX SEC‑3100, and CHARX SEC‑3150. No specific firmware or software version numbers are listed, so any system running these models is vulnerable unless a fix has been applied.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as High severity, and the EPSS score of 1% indicates that while the likelihood of exploitation is low, it is not negligible. The vulnerability is not currently listed in CISA’s KEV catalog. An attacker can exploit it remotely without authentication by controlling the OCPP backend, typically after establishing a firewall bypass. Successful exploitation grants arbitrary command execution as the charx-oa user, which can stop charging and potentially be used as a foothold for further attacks within the local network.
OpenCVE Enrichment