Description
The firmware update process for the basemodule of the charging controller only validates the
CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.
Published: 2026-07-30
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The firmware update mechanism for Phoenix Contact charging controllers validates only a CRC32 checksum and does not perform cryptographic signature verification. Because a firmware file can be altered without detection, an unauthenticated attacker can supply a malicious binary, leading to full system compromise. This weakness corresponds to CWE‑347.

Affected Systems

Affected vendor: Phoenix Contact. Products: CHARX SEC‑3000, CHARX SEC‑3050, CHARX SEC‑3100, CHARX SEC‑3150. Version information is not supplied, so all listed models are considered affected pending further details from Phoenix Contact.

Risk and Exploitability

The CVSS score of 9.3 indicates high severity. The EPSS score of < 1% suggests a low, though non‑zero, likelihood of active exploitation. The vulnerability is not yet listed in the CISA KEV catalog. The likely exploitation path involves an unauthenticated remote attacker sending a forged firmware image to the controller, exploiting the lack of signature enforcement and producing remote code execution and complete takeover of the system. No authentication barrier exists, and the attack is feasible from a remote location as long as the controller is reachable over the network.

Generated by OpenCVE AI on August 3, 2026 at 11:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest Phoenix Contact firmware update that implements cryptographic signature verification for the base module, ensuring the updater no longer relies solely on CRC32 checksums.
  • If a patched firmware is not immediately available, temporarily disable the controller’s remote firmware update feature or block its network port until a secure update mechanism is in place.
  • Implement network segmentation or firewall rules that limit who can reach the controller’s update endpoint, and monitor for any unauthorized firmware upload attempts.

Generated by OpenCVE AI on August 3, 2026 at 11:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150
Vendors & Products Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.
Title ControllerAgent does not perform validation of firmware
First Time appeared Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
Weaknesses CWE-347
CPEs cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Charx Sec 3000 Charx Sec 3050 Charx Sec 3100 Charx Sec 3150
Phoenixcontact Charx Sec-3000 Charx Sec-3050 Charx Sec-3100 Charx Sec-3150
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-30T14:05:46.344Z

Reserved: 2026-05-05T10:48:08.226Z

Link: CVE-2026-44104

cve-icon Vulnrichment

Updated: 2026-07-30T14:05:34.465Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T07:16:58.760

Modified: 2026-07-30T15:16:33.297

Link: CVE-2026-44104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:03Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature