Description
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
Published: 2026-07-30
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a command injection flaw caused by improper neutralization of special elements within the idledisconnect parameter of the SCM interface. An unauthenticated remote attacker can inject arbitrary shell commands that are executed with root privileges on the affected device. The flaw is classified as CWE‑77 and allows total compromise of confidentiality, integrity, and availability.

Affected Systems

Affected devices are the Phoenix Contact CHARX SEC‑3000, CHARX SEC‑3050, CHARX SEC‑3100, and CHARX SEC‑3150 series. No specific firmware or software revisions are mentioned, so all current releases of these models are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 9.3 marks the flaw as critical, while the EPSS score of less than 1 % suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. An attacker must directly communicate with the SCM interface and supply a crafted idledisconnect parameter to trigger the injection; no authentication is required, indicating a high level of accessibility. If exploited, the attacker gains unrestricted root access and could manipulate any system component, installing malware, exfiltrating data, or disrupting operations.

Generated by OpenCVE AI on August 3, 2026 at 11:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest official firmware or software update from Phoenix Contact that resolves the command injection flaw in the SCM interface.
  • Restrict external access to the device’s SCM management interface by placing it behind a firewall or VPN and limiting connections to trusted internal hosts.
  • If an update is not yet available, block or filter traffic that includes the idledisconnect parameter or otherwise whitelist only authenticated and authorized management traffic to reduce the attack surface.

Generated by OpenCVE AI on August 3, 2026 at 11:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150
Vendors & Products Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
Title Command Injection in SCM (idledisconnect parameter)
First Time appeared Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
Weaknesses CWE-77
CPEs cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Charx Sec 3000 Charx Sec 3050 Charx Sec 3100 Charx Sec 3150
Phoenixcontact Charx Sec-3000 Charx Sec-3050 Charx Sec-3100 Charx Sec-3150
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-30T14:06:42.780Z

Reserved: 2026-05-05T10:57:27.620Z

Link: CVE-2026-7849

cve-icon Vulnrichment

Updated: 2026-07-30T14:06:39.219Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T07:16:59.443

Modified: 2026-07-30T15:16:37.673

Link: CVE-2026-7849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:03Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')