CVE-2025-25271: OCPP Backend Configuration via Insecure Defaults
An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25271?
CVE-2025-25271 is classified as a high severity vulnerability due to the potential for unauthorized configuration by adjacent attackers.
How do I fix CVE-2025-25271?
To fix CVE-2025-25271, update the affected Phoenix Contact Charx Sec firmware to version 1.7.3 or later.
What products are affected by CVE-2025-25271?
CVE-2025-25271 affects the Phoenix Contact Charx Sec-3000, -3050, -3100, and -3150 firmware versions prior to 1.7.3.
Can CVE-2025-25271 be exploited remotely?
CVE-2025-25271 cannot be exploited remotely, but requires an unauthenticated nearby attacker to access the configuration interface.
What are the implications of CVE-2025-25271?
The implications of CVE-2025-25271 include the risk of unauthorized configuration changes to the OCPP backend, potentially compromising the system's integrity.