๐Ÿ” CVE Alert

CVE-2026-44104

CRITICAL 9.8

ControllerAgent does not perform validation of firmware

CVSS Score
9.8
EPSS Score
0.2%
EPSS Percentile
15th

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.

CWE CWE-347
Vendor phoenix contact
Product charx sec-3150
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for phoenix contact charx sec-3150

Be the first to know when new critical vulnerabilities affecting phoenix contact charx sec-3150 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Phoenix Contact / CHARX SEC-3150
1.0.0 < 1.9.1
Phoenix Contact / CHARX SEC-3100
1.0.0 < 1.9.1
Phoenix Contact / CHARX SEC-3050
1.0.0 < 1.9.1
Phoenix Contact / CHARX SEC-3000
1.0.0 < 1.9.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
certvde.com: https://www.certvde.com/en/advisories/VDE-2026-008/

Credits

ZDI