Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CHARX SEC-3150 — Vulnerabilities & Security Advisories 31

All 31 CVE vulnerabilities found in CHARX SEC-3150, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the CHARX SEC-3150 industrial secure communication device manufactured by CHARX Technology. It aggregates known security flaws, configuration misconfigurations, and implementation errors specifically affecting this hardware and its associated firmware versions. The content covers a comprehensive time range spanning from the initial release of the product through the present, ensuring that both historical and newly disclosed issues are captured for thorough analysis. Visitors to this page can effectively track advisory announcements issued by CHARX Technology regarding the SEC-3150, allowing them to stay informed about critical patches and mitigation strategies as they become available. The collected data provides a clear understanding of prevalent weakness classes within this specific product line, helping security professionals identify patterns in how similar vulnerabilities manifest across different updates. Additionally, users can look up the complete vulnerability history of the SEC-3150 to assess the product’s long-term security posture and compliance status. This resource is designed to support risk assessments, penetration testing validations, and ongoing maintenance planning for organizations relying on this equipment. By centralizing this information, the page serves as a single point of reference for evaluating the security landscape of the CHARX SEC-3150 without requiring extensive manual research across multiple disparate sources.

Vendor: Phoenix Contact

CVE ID Title CVSS Severity Published
CVE-2026-7849 Command Injection in SCM (idledisconnect parameter) CWE-77 9.8 Critical 2026-07-30
CVE-2026-44108 Firewall bypass during shutdown CWE-696 9.8 Critical 2026-07-30
CVE-2026-44107 Exposed Reboot via Modbus CWE-749 7.5 High 2026-07-30
CVE-2026-44105 Cleartext password in logs CWE-532 6.6 Medium 2026-07-30
CVE-2026-44106 Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website file CWE-78 7.8 High 2026-07-30
CVE-2026-44104 ControllerAgent does not perform validation of firmware CWE-347 9.8 Critical 2026-07-30
CVE-2026-44103 JupiCore does not perform validation of firmware CWE-434 5.3 Medium 2026-07-30
CVE-2026-44102 OCPP Firmware download is not properly locked CWE-362 5.3 Medium 2026-07-30
CVE-2026-44101 OCPP reconfiguration vulnerability CWE-306 9.8 Critical 2026-07-30
CVE-2026-44100 JupiCore charging point reconfiguration without auth CWE-306 9.4 Critical 2026-07-30
CVE-2026-44099 Local Privilege Escalation via pppd password injection CWE-78 7.8 High 2026-07-30
CVE-2026-44098 OS Command Injection in OCPP Agent via charge_box_id CWE-78 8.6 High 2026-07-30
CVE-2026-44097 File Upload vulnerability CWE-434 7.1 High 2026-07-30
CVE-2026-44096 udhcpc Privilege Escalation CWE-78 7.8 High 2026-07-30
CVE-2026-44095 Local Privilege Escalation via Network scripts CWE-78 7.8 High 2026-07-30
CVE-2026-44094 Fallback to second RAUC slot with default credentials CWE-636 8.6 High 2026-07-30
CVE-2026-44093 Local Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start script CWE-78 7.8 High 2026-07-30
CVE-2026-44092 Missing input validation / stripping of CRLF characters in SystemConfigManager CWE-93 9.1 Critical 2026-07-30
CVE-2026-44091 Creation of a new configuration by posting a malicious ID to MQTT CWE-501 9.1 Critical 2026-07-30
CVE-2026-44090 Missing authentication for MQTT Broker CWE-306 9.8 Critical 2026-07-30
CVE-2026-41032 Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers CWE-200 7.5 High 2026-06-03
CVE-2025-41699 Phoenix Contact: Security Advisory for CHARX SEC-3xxx charging controllers CWE-94 8.8 High 2025-10-14
CVE-2025-25271 OCPP Backend Configuration via Insecure Defaults CWE-1188 8.8 High 2025-07-08
CVE-2025-25270 Remote Code Execution via Unauthenticated Configuration Manipulation CWE-913 9.8 Critical 2025-07-08
CVE-2025-25269 Local Privilege Escalation via Unauthenticated Command Injection CWE-78 8.4 High 2025-07-08
CVE-2025-25268 Unauthenticated Configuration Access via Exposed API Endpoint CWE-306 8.8 High 2025-07-08
CVE-2025-24006 Privilege Escalation via Insecure SSH Permissions CWE-269 7.8 High 2025-07-08
CVE-2025-24005 Local Privilege Escalation via Vulnerable SSH Script CWE-20 7.8 High 2025-07-08
CVE-2025-24004 USB-C Buffer Overflow via Display Interface in EV Charging Stations CWE-120 5.2 Medium 2025-07-08
CVE-2025-24003 MQTT OOB Write Vulnerability in EichrechtAgents of German EV Charging Stations CWE-120 8.2 High 2025-07-08

All 31 known CVE vulnerabilities affecting CHARX SEC-3150 with full Chinese analysis, references, and POCs where available.