CVEs (29)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJul 11, 2025 Jul 8, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJul 11, 2025 Jul 8, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJul 11, 2025 Jul 8, 2025 N/A· v4 8.4 HIGH· v3 N/A· v2 An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJul 11, 2025 Jul 8, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJul 11, 2025 Jul 8, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJul 11, 2025 Jul 8, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJul 11, 2025 Jul 8, 2025 N/A· v4 5.2 MEDIUM· v3 N/A· v2 A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the statio...Show more |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJul 11, 2025 Jul 8, 2025 N/A· v4 8.2 HIGH· v3 N/A· v2 An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only EichrechtAgents and potential...Show more |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJul 11, 2025 Jul 8, 2025 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restart...Show more |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreAug 22, 2025 Aug 13, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJan 29, 2025 Aug 13, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJan 23, 2025 May 14, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2
A local attacker with low privileges can perform a privilege escalation with an init script due to a TOCTOU vulnerability.
|
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJan 24, 2025 May 14, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A local attacker with low privileges can use a command injection vulnerability to gain root
privileges due to improper input validation using the OCPP Remote service. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJan 24, 2025 May 14, 2024 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A low privileged remote attacker can use a command injection vulnerability in the API which performs
remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJan 23, 2025 May 14, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently l...Show more |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJan 23, 2025 May 14, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2
A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root
privileges.
|
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJan 23, 2025 Mar 12, 2024 N/A· v4 8.7 HIGH· v3 N/A· v2 An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJan 23, 2025 Mar 12, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJan 23, 2025 Mar 12, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality. |
1Phoenixcontact 4Charx Sec 3000 Firmware Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 moreJan 23, 2025 Mar 12, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality. |