Description
An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.
Published: 2026-07-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated remote attacker can inject malicious firmware because the JupiCore service transmits firmware updates without performing an integrity or verification check. This weakness, which corresponds to CWE-434, can compromise the integrity of the device and potentially provide the attacker with unauthorized control or additional attack vectors when chained with CVE-2026-44104.

Affected Systems

The vulnerability affects Phoenix Contact’s JupiCore-enabled devices, specifically the CHARX SEC-3000, CHARX SEC-3050, CHARX SEC-3100, and CHARX SEC-3150 models. No specific firmware revisions are listed in the public data, so all revisions of these models are considered potentially vulnerable.

Risk and Exploitability

Based on the description, the likely attack vector is internal or on an unprotected network segment that can reach the JupiCore service. The CVSS score of 6.9 indicates moderate severity. The EPSS score of less than 1% suggests a low but nonzero likelihood of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Successful exploitation would give the attacker the ability to replace legitimate firmware with malicious code, jeopardizing device integrity and potentially enabling further compromise.

Generated by OpenCVE AI on August 2, 2026 at 05:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official firmware update or patch released by Phoenix Contact to address the unvalidated firmware vulnerability.
  • Segment the network to restrict access to the JupiCore service, ensuring only trusted devices can initiate firmware updates.
  • Enable and review logging of firmware update attempts on the JupiCore service to detect unauthorized or anomalous activity.

Generated by OpenCVE AI on August 2, 2026 at 05:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150
Vendors & Products Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.
Title JupiCore does not perform validation of firmware
First Time appeared Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
Weaknesses CWE-434
CPEs cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Charx Sec 3000 Charx Sec 3050 Charx Sec 3100 Charx Sec 3150
Phoenixcontact Charx Sec-3000 Charx Sec-3050 Charx Sec-3100 Charx Sec-3150
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-30T12:56:38.642Z

Reserved: 2026-05-05T10:48:08.226Z

Link: CVE-2026-44103

cve-icon Vulnrichment

Updated: 2026-07-30T12:56:35.609Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T07:16:58.620

Modified: 2026-07-30T14:31:21.447

Link: CVE-2026-44103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:45:03Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type