CVE-2025-24006: Privilege Escalation via Insecure SSH Permissions
Published Jul 8, 2025
·Updated
A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root.
Affected Software
8 affected components
All of the following
Phoenixcontact Charx Sec-3000 Firmware<1.7.3
Phoenixcontact Charx Sec-3000
All of the following
Phoenixcontact Charx Sec-3050 Firmware<1.7.3
Phoenixcontact Charx Sec-3050
All of the following
Phoenixcontact Charx Sec-3100 Firmware<1.7.3
Phoenixcontact Charx Sec-3100
All of the following
Phoenixcontact Charx Sec-3150 Firmware<1.7.3
Phoenixcontact Charx Sec-3150
Event History
Jul 8, 2025
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24006?
CVE-2025-24006 has a low severity rating, but it allows local attackers with low privileges to escalate to root.
2
How do I fix CVE-2025-24006?
To fix CVE-2025-24006, update all affected Phoenix Contact Charx Sec firmware to version 1.7.3 or later.
3
Which devices are affected by CVE-2025-24006?
CVE-2025-24006 affects the Phoenix Contact Charx Sec-3000, Charx Sec-3050, Charx Sec-3100, and Charx Sec-3150 firmware versions prior to 1.7.3.
4
Who can exploit CVE-2025-24006?
CVE-2025-24006 can be exploited by local attackers with low privileges via SSH on the affected devices.
5
What can an attacker achieve by exploiting CVE-2025-24006?
An attacker exploiting CVE-2025-24006 can escalate their privileges to root on the affected devices.