Impact
The firmware update mechanism for Phoenix Contact charging controllers validates only a CRC32 checksum and does not perform cryptographic signature verification. Because a firmware file can be altered without detection, an unauthenticated attacker can supply a malicious binary, leading to full system compromise. This weakness corresponds to CWE‑347.
Affected Systems
Affected vendor: Phoenix Contact. Products: CHARX SEC‑3000, CHARX SEC‑3050, CHARX SEC‑3100, CHARX SEC‑3150. Version information is not supplied, so all listed models are considered affected pending further details from Phoenix Contact.
Risk and Exploitability
The CVSS score of 9.3 indicates high severity. The EPSS score of < 1% suggests a low, though non‑zero, likelihood of active exploitation. The vulnerability is not yet listed in the CISA KEV catalog. The likely exploitation path involves an unauthenticated remote attacker sending a forged firmware image to the controller, exploiting the lack of signature enforcement and producing remote code execution and complete takeover of the system. No authentication barrier exists, and the attack is feasible from a remote location as long as the controller is reachable over the network.
OpenCVE Enrichment