๐Ÿ” CVE Alert

CVE-2026-44103

MEDIUM 5.3

JupiCore does not perform validation of firmware

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.

CWE CWE-434
Vendor phoenix contact
Product charx sec-3150
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for phoenix contact charx sec-3150

Be the first to know when new medium vulnerabilities affecting phoenix contact charx sec-3150 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Phoenix Contact / CHARX SEC-3150
1.0.0 < 1.9.1
Phoenix Contact / CHARX SEC-3100
1.0.0 < 1.9.1
Phoenix Contact / CHARX SEC-3050
1.0.0 < 1.9.1
Phoenix Contact / CHARX SEC-3000
1.0.0 < 1.9.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
certvde.com: https://www.certvde.com/en/advisories/VDE-2026-008/

Credits

ZDI