Phoenix Contact CHARX SEC-3150是德国菲尼克斯电气(Phoenix Contact)公司的一款交流充电控制器。 Phoenix Contact CHARX SEC-3150存在代码注入漏洞,该漏洞源于低权限远程攻击者可通过基于Web的管理账户更改系统配置执行命令注入,导致代码生成控制不当,可能完全丧失机密性、可用性和完整性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Phoenix Contact | CHARX SEC-3150 | 0.0.0 ~ 1.7.4 | - |
|
| Phoenix Contact | CHARX SEC-3100 | 0.0.0 ~ 1.7.4 | - |
|
| Phoenix Contact | CHARX SEC-3050 | 0.0.0 ~ 1.7.4 | - |
|
| Phoenix Contact | CHARX SEC-3000 | 0.0.0 ~ 1.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-41703 | 7.5 HIGH | Phoenix Contact: UPS Shutdown via Unauthenticated Modbus Command |
| CVE-2025-41705 | 6.8 MEDIUM | Phoenix Contact: WebSocket Message Interception Leaks Webfrontend Credentials |
| CVE-2025-41704 | 5.3 MEDIUM | Phoenix Contact: Unauthenticated Modbus Service DoS via Crafted Function Code |
| CVE-2025-41706 | 5.3 MEDIUM | Phoenix Contact: Webserver Denial of Service through Malformed Content-Length |
| CVE-2025-41707 | 5.3 MEDIUM | Phoenix Contact: WebSocket Handler Denial of Service |
No comments yet