Impact
An unauthenticated attacker can trigger a firmware download by sending an invalid firmware file to the OCPP backend. The invalid file is stored temporarily, and due to improper locking in the cleanup process, it remains accessible for a brief period before deletion. This race condition (CWE‑362) allows the attacker to download the firmware binary without authorization. The vulnerability exists in the firmware update handling component that uses the Open Charge Point Protocol (OCPP) backend.
Affected Systems
The affected products are Phoenix Contact’s CHARX SEC series industrial controls: CHARX SEC‑3000, SEC‑3050, SEC‑3100, and SEC‑3150. Devices running any version of these models are potentially impacted. The vulnerability exists in the firmware update handling component that uses the Open Charge Point Protocol (OCPP) backend.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. The EPSS score is under 1 %, suggesting a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via the OCPP backend interface, and does not require local privileges. If an attacker can reach this interface, they can exploit the race condition to obtain firmware files. Because the window is short, the success rate depends on timing, but once the file is available, the exploitation is straightforward.
OpenCVE Enrichment