Description
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.
Published: 2026-07-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CHARX JupiCore service in Phoenix Contact charging point controllers suffers from a missing authentication weakness (CWE-306). An attacker who can reach the service can reconfigure charging points without credentials, potentially exposing charging point unique identifiers, causing denial‑of‑service conditions, and tampering with configuration files. The impact is loss of confidentiality for UIDs, integrity of configuration data, and availability of the charging infrastructure.

Affected Systems

Affected models are the Phoenix Contact CHARX SEC‑3000, SEC‑3050, SEC‑3100 and SEC‑3150. No explicit firmware or software version information was supplied, so any device running the JupiCore service is potentially vulnerable. The CPE strings for these models confirm the scope of impact.

Risk and Exploitability

The CVSS score of 8.8 judges the severity as high. The EPSS score of less than 1 % indicates a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote; an adversary would need network access to the JupiCore service, which is typically exposed on a local or wide‑area network. No additional prerequisites are described, so the vulnerability appears to be reachable by any host that can connect to the service's port.

Generated by OpenCVE AI on August 3, 2026 at 11:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the firmware or software of all Phoenix Contact CHARX SEC‑3000, SEC‑3050, SEC‑3100 and SEC‑3150 units to the latest vendor release that includes authentication for the JupiCore service.
  • Restrict the network exposure of the JupiCore service by limiting access to trusted IP ranges, applying firewall rules, or requiring VPN connectivity before any configuration traffic can reach the device.
  • Monitor device logs for unexpected configuration changes and conduct regular audits to detect unauthorized reconfiguration attempts.

Generated by OpenCVE AI on August 3, 2026 at 11:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150
Vendors & Products Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.
Title JupiCore charging point reconfiguration without auth
First Time appeared Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
Weaknesses CWE-306
CPEs cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Charx Sec 3000 Charx Sec 3050 Charx Sec 3100 Charx Sec 3150
Phoenixcontact Charx Sec-3000 Charx Sec-3050 Charx Sec-3100 Charx Sec-3150
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-30T12:29:40.648Z

Reserved: 2026-05-05T10:48:08.226Z

Link: CVE-2026-44100

cve-icon Vulnrichment

Updated: 2026-07-30T12:29:32.604Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T07:16:58.220

Modified: 2026-07-30T14:31:21.447

Link: CVE-2026-44100

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function