Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PHOENIX CONTACT — Vulnerabilities & Security Advisories 169

Browse all 169 CVE security advisories affecting PHOENIX CONTACT. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PHOENIX CONTACT specializes in industrial automation, electrical engineering, and electronics, providing critical infrastructure components such as programmable logic controllers, power supplies, and industrial networking devices. With 142 recorded CVEs, the company’s software ecosystem has historically been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These flaws often stem from inadequate input validation in web-based management interfaces or insecure default configurations in embedded systems. Notable incidents include exploitable authentication bypasses and buffer overflow errors that could allow attackers to gain unauthorized control over industrial control systems. The high volume of vulnerabilities suggests persistent challenges in securing legacy firmware and web applications. While the hardware itself is robust, the associated software layers require rigorous patching and secure coding practices to mitigate risks in operational technology environments.

Found 31 results / 169 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-7849 Command Injection in SCM (idledisconnect parameter) — CHARX SEC-3150 CWE-77 9.8 Critical 2026-07-30
CVE-2026-44108 Firewall bypass during shutdown — CHARX SEC-3150 CWE-696 9.8 Critical 2026-07-30
CVE-2026-44107 Exposed Reboot via Modbus — CHARX SEC-3150 CWE-749 7.5 High 2026-07-30
CVE-2026-44105 Cleartext password in logs — CHARX SEC-3150 CWE-532 6.6 Medium 2026-07-30
CVE-2026-44106 Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website file — CHARX SEC-3150 CWE-78 7.8 High 2026-07-30
CVE-2026-44104 ControllerAgent does not perform validation of firmware — CHARX SEC-3150 CWE-347 9.8 Critical 2026-07-30
CVE-2026-44103 JupiCore does not perform validation of firmware — CHARX SEC-3150 CWE-434 5.3 Medium 2026-07-30
CVE-2026-44102 OCPP Firmware download is not properly locked — CHARX SEC-3150 CWE-362 5.3 Medium 2026-07-30
CVE-2026-44101 OCPP reconfiguration vulnerability — CHARX SEC-3150 CWE-306 9.8 Critical 2026-07-30
CVE-2026-44100 JupiCore charging point reconfiguration without auth — CHARX SEC-3150 CWE-306 9.4 Critical 2026-07-30
CVE-2026-44099 Local Privilege Escalation via pppd password injection — CHARX SEC-3150 CWE-78 7.8 High 2026-07-30
CVE-2026-44098 OS Command Injection in OCPP Agent via charge_box_id — CHARX SEC-3150 CWE-78 8.6 High 2026-07-30
CVE-2026-44097 File Upload vulnerability — CHARX SEC-3150 CWE-434 7.1 High 2026-07-30
CVE-2026-44096 udhcpc Privilege Escalation — CHARX SEC-3150 CWE-78 7.8 High 2026-07-30
CVE-2026-44095 Local Privilege Escalation via Network scripts — CHARX SEC-3150 CWE-78 7.8 High 2026-07-30
CVE-2026-44094 Fallback to second RAUC slot with default credentials — CHARX SEC-3150 CWE-636 8.6 High 2026-07-30
CVE-2026-44093 Local Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start script — CHARX SEC-3150 CWE-78 7.8 High 2026-07-30
CVE-2026-44092 Missing input validation / stripping of CRLF characters in SystemConfigManager — CHARX SEC-3150 CWE-93 9.1 Critical 2026-07-30
CVE-2026-44091 Creation of a new configuration by posting a malicious ID to MQTT — CHARX SEC-3150 CWE-501 9.1 Critical 2026-07-30
CVE-2026-44090 Missing authentication for MQTT Broker — CHARX SEC-3150 CWE-306 9.8 Critical 2026-07-30
CVE-2026-41032 Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers — CHARX SEC-3150 CWE-200 7.5 High 2026-06-03
CVE-2025-41699 Phoenix Contact: Security Advisory for CHARX SEC-3xxx charging controllers — CHARX SEC-3150 CWE-94 8.8 High 2025-10-14
CVE-2025-25271 OCPP Backend Configuration via Insecure Defaults — CHARX SEC-3150 CWE-1188 8.8 High 2025-07-08
CVE-2025-25270 Remote Code Execution via Unauthenticated Configuration Manipulation — CHARX SEC-3150 CWE-913 9.8 Critical 2025-07-08
CVE-2025-25269 Local Privilege Escalation via Unauthenticated Command Injection — CHARX SEC-3150 CWE-78 8.4 High 2025-07-08
CVE-2025-25268 Unauthenticated Configuration Access via Exposed API Endpoint — CHARX SEC-3150 CWE-306 8.8 High 2025-07-08
CVE-2025-24006 Privilege Escalation via Insecure SSH Permissions — CHARX SEC-3150 CWE-269 7.8 High 2025-07-08
CVE-2025-24005 Local Privilege Escalation via Vulnerable SSH Script — CHARX SEC-3150 CWE-20 7.8 High 2025-07-08
CVE-2025-24004 USB-C Buffer Overflow via Display Interface in EV Charging Stations — CHARX SEC-3150 CWE-120 5.2 Medium 2025-07-08
CVE-2025-24003 MQTT OOB Write Vulnerability in EichrechtAgents of German EV Charging Stations — CHARX SEC-3150 CWE-120 8.2 High 2025-07-08

This page lists every published CVE security advisory associated with PHOENIX CONTACT. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.