Back to overview

Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers

VDE-2026-060
Last update
06/03/2026 12:01
Published at
06/03/2026 12:00
Vendor(s)
Phoenix Contact GmbH & Co. KG
External ID
VDE-2026-060
CSAF Document

Summary

VDE-2026-060: A unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers has been discovered.

Impact

The vulnerability can lead to restricted information being disclosed to an unauthenticated attacker.

Affected Product(s)

Model no. Product name Affected versions
1139022 CHARX SEC-3000 Firmware <1.9.0
1139018 CHARX SEC-3050 Firmware <1.9.0
1139012 CHARX SEC-3100 Firmware <1.9.0
1138965 CHARX SEC-3150 Firmware <1.9.0

Vulnerabilities

Expand / Collapse all

Published
06/03/2026 10:50
Weakness
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200)
Summary

It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.

References

Mitigation

Affected charging controllers are designed and developed for the use in closed industrial networks. Phoenix Contact therefore strongly recommends using the devices exclusively in closed networks and protected by a suitable firewall.

Remediation

Phoenix Contact recommends to upgrade to firmware version 1.9.0 which fixes this vulnerability.

Acknowledgments

Phoenix Contact GmbH & Co. KG thanks the following parties for their efforts:

Revision History

Version Date Summary
1.0.0 06/03/2026 12:00 Initial revision
1.0.1 06/03/2026 12:01 added "Firmware" to the textual description of the relationships.