← Back

Phoenixcontact

phoenixcontact

156 CVEs • 680 products

Products (680)

Click to collapse
Toggle

CVEs (156)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phoenixcontact
4Charx Sec 3000 Firmware
Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 more
Jun 17, 2026
Jul 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation.
1Phoenixcontact
4Charx Sec 3000 Firmware
Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 more
Jun 17, 2026
Jul 8, 2025
N/A· v4
5.2 MEDIUM· v3
N/A· v2
A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the statio...Show more
A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the stations until they got restarted by the watchdog.Show less
1Phoenixcontact
4Charx Sec 3000 Firmware
Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 more
Jun 17, 2026
Jul 8, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only EichrechtAgents and potential...Show more
An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only EichrechtAgents and potential denial-of-service for these stations.Show less
1Phoenixcontact
4Charx Sec 3000 Firmware
Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 more
Jun 17, 2026
Jul 8, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restart...Show more
An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restarted by the watchdog.Show less
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_...Show more
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP FW_RULESETS.IN_IP environment variable which can lead to a DoS.Show less
1Phoenixcontact
30Fl Mguard Centerport Vpn 1000 Firmware
Fl Mguard Core Tx FirmwareFl Mguard Core Tx Vpn Firmware+27 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_...Show more
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable which can lead to a DoS.Show less
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment vari...Show more
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS.Show less
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS.
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices.
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices.
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited...Show more
An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers.Show less
1Phoenixcontact
4Charx Sec 3000 Firmware
Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 more
Jun 17, 2026
Aug 13, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.
1Phoenixcontact
4Charx Sec 3000 Firmware
Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 more
Jun 17, 2026
Aug 13, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.
1Phoenixcontact
4Charx Sec 3000 Firmware
Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 more
Jun 17, 2026
May 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A local attacker with low privileges can perform a privilege escalation with an init script due to a TOCTOU vulnerability.
1Phoenixcontact
4Charx Sec 3000 Firmware
Charx Sec 3050 FirmwareCharx Sec 3100 Firmware+1 more
Jun 17, 2026
May 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service.