PHOENIX CONTACT CHARX SEC-3150是德国PHOENIX CONTACT公司的电动车充电站。 PHOENIX CONTACT CHARX SEC-3150 1.0.0版本至1.9.1之前版本存在日志信息泄露漏洞,该漏洞源于本地用户"user-app"的凭据可能暴露在日志文件中,可能导致低权限本地攻击者通过SSH认证为受限用户"user-app",从而中断充电。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Phoenix Contact | CHARX SEC-3000 | 1.0.0< 1.9.1 |
affected |
| Phoenix Contact | CHARX SEC-3050 | 1.0.0< 1.9.1 |
affected |
| Phoenix Contact | CHARX SEC-3100 | 1.0.0< 1.9.1 |
affected |
| Phoenix Contact | CHARX SEC-3150 | 1.0.0< 1.9.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Phoenix Contact | CHARX SEC-3150 | 1.0.0 ~ 1.9.1 | - |
|
| Phoenix Contact | CHARX SEC-3100 | 1.0.0 ~ 1.9.1 | - |
|
| Phoenix Contact | CHARX SEC-3050 | 1.0.0 ~ 1.9.1 | - |
|
| Phoenix Contact | CHARX SEC-3000 | 1.0.0 ~ 1.9.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7849 | 9.8 CRITICAL | Command Injection in SCM (idledisconnect parameter) |
| CVE-2026-44101 | 9.8 CRITICAL | OCPP reconfiguration vulnerability |
| CVE-2026-44090 | 9.8 CRITICAL | Missing authentication for MQTT Broker |
| CVE-2026-44104 | 9.8 CRITICAL | ControllerAgent does not perform validation of firmware |
| CVE-2026-44108 | 9.8 CRITICAL | Firewall bypass during shutdown |
| CVE-2026-44100 | 9.4 CRITICAL | JupiCore charging point reconfiguration without auth |
| CVE-2026-44091 | 9.1 CRITICAL | Creation of a new configuration by posting a malicious ID to MQTT |
| CVE-2026-44092 | 9.1 CRITICAL | Missing input validation / stripping of CRLF characters in SystemConfigManager |
| CVE-2026-44094 | 8.6 HIGH | Fallback to second RAUC slot with default credentials |
| CVE-2026-44098 | 8.6 HIGH | OS Command Injection in OCPP Agent via charge_box_id |
| CVE-2026-44099 | 7.8 HIGH | Local Privilege Escalation via pppd password injection |
| CVE-2026-44096 | 7.8 HIGH | udhcpc Privilege Escalation |
| CVE-2026-44093 | 7.8 HIGH | Local Privilege Escalation vulnerability in /etc/init.d/user-applications via user-applica |
| CVE-2026-44106 | 7.8 HIGH | Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer web |
| CVE-2026-44095 | 7.8 HIGH | Local Privilege Escalation via Network scripts |
| CVE-2026-44107 | 7.5 HIGH | Exposed Reboot via Modbus |
| CVE-2026-44097 | 7.1 HIGH | File Upload vulnerability |
| CVE-2026-44102 | 5.3 MEDIUM | OCPP Firmware download is not properly locked |
| CVE-2026-44103 | 5.3 MEDIUM | JupiCore does not perform validation of firmware |
No comments yet