VendorsPHOENIX CONTACTcharx_sec-3000_firmwareany version
Vulnerabilities

PHOENIX CONTACT CHARX SEC-3000 Firmware any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2024-25995
PHOENIX CONTACT: Remote code execution in CHARX Series
Published 2024-03-12 · Modified
9.8EPSS 0.014
CVE-2024-26001
PHOENIX CONTACT: Out of bounds write only memory access
Published 2024-03-12 · Modified
9.8EPSS 0.009
CVE-2025-25270
Remote Code Execution via Unauthenticated Configuration Manipulation
Published 2025-07-08 · Analyzed
9.8EPSS 0.007
CVE-2024-6788
Phoenix Contact: update feature from CHARX controller can be used to reset a low privilege user password
Published 2024-08-13 · Modified
9.8EPSS 0.005
CVE-2024-25996
PHOENIX CONTACT: Remote code execution due to an origin validation error in CHARX Series
Published 2024-03-12 · Analyzed
9.8EPSS 0.004
CVE-2025-25268
Unauthenticated Configuration Access via Exposed API Endpoint
Published 2025-07-08 · Analyzed
8.8EPSS 0.003
CVE-2025-25271
OCPP Backend Configuration via Insecure Defaults
Published 2025-07-08 · Analyzed
8.8EPSS 0.003
CVE-2024-26288
PHOENIX CONTACT: Lack of SSL support in CHARX Series
Published 2024-03-12 · Analyzed
8.7EPSS 0.003
CVE-2024-25999
PHOENIX CONTACT: Privilege escalation in the OCPP agent service
Published 2024-03-12 · Analyzed
8.4EPSS 0.004
CVE-2025-25269
Local Privilege Escalation via Unauthenticated Command Injection
Published 2025-07-08 · Analyzed
8.4EPSS 0.003
CVE-2025-24003
MQTT OOB Write Vulnerability in EichrechtAgents of German EV Charging Stations
Published 2025-07-08 · Analyzed
8.2EPSS 0.003
CVE-2024-28136
PHOENIX CONTACT: command injection gains root privileges using the OCPP remote service
Published 2024-05-14 · Modified
7.8EPSS 0.008
CVE-2024-28133
PHOENIX CONTACT: Privilege escalation in CHARX Series
Published 2024-05-14 · Analyzed
7.8EPSS 0.004
CVE-2024-26002
PHOENIX CONTACT: File ownership manipulation in CHARX Series
Published 2024-03-12 · Analyzed
7.8EPSS 0.003
CVE-2024-28137
PHOENIX CONTACT: privilege escalation due to a TOCTOU vulnerability in the CHARX Series
Published 2024-05-14 · Analyzed
7.8EPSS 0.003
CVE-2025-24005
Local Privilege Escalation via Vulnerable SSH Script
Published 2025-07-08 · Analyzed
7.8EPSS 0.001
CVE-2025-24006
Privilege Escalation via Insecure SSH Permissions
Published 2025-07-08 · Analyzed
7.8EPSS 0.001
CVE-2024-26003
PHOENIX CONTACT: DoS of the control agent in CHARX Series
Published 2024-03-12 · Analyzed
7.5EPSS 0.012
CVE-2024-26004
PHOENIX CONTACT: DoS of a control agent due to access of a uninitialized pointer in CHARX Series
Published 2024-03-12 · Analyzed
7.5EPSS 0.010
CVE-2024-26000
PHOENIX CONTACT: Out of bounds read only memory access
Published 2024-03-12 · Modified
7.5EPSS 0.008
CVE-2024-25998
PHOENIX CONTACT: Command injection in the OCPP Service
Published 2024-03-12 · Modified
7.3EPSS 0.015
CVE-2024-28134
PHOENIX CONTACT: MitM attack gains privileges of the current logged in user in CHARX Series
Published 2024-05-14 · Analyzed
7.0EPSS 0.005
CVE-2024-3913
Phoenix Contact: Start sequence allows attack during the boot process
Published 2024-08-13 · Modified
5.9EPSS 0.005
CVE-2024-25994
PHOENIX CONTACT: Unintended script file upload in CHARX Series
Published 2024-03-12 · Modified
5.3EPSS 0.007
CVE-2024-25997
PHOENIX CONTACT: Log injection in CHARX Series
Published 2024-03-12 · Analyzed
5.3EPSS 0.007
CVE-2025-24002
MQTT DoS Vulnerability in German EV Charging Stations
Published 2025-07-08 · Analyzed
5.3EPSS 0.004
CVE-2025-24004
USB-C Buffer Overflow via Display Interface in EV Charging Stations
Published 2025-07-08 · Analyzed
5.2EPSS 0.002
CVE-2024-28135
PHOENIX CONTACT: command injection vulnerability in the API of the CHARX Series
Published 2024-05-14 · Modified
5.0EPSS 0.013
CVE-2024-26005
PHOENIX CONTACT: Privilege gain through incomplete cleanup in CHARX Series
Published 2024-03-12 · Analyzed
4.8EPSS 0.006