CVE-2025-41699: Phoenix Contact: Security Advisory for CHARX SEC-3xxx charging controllers
An low privileged remote attacker with an account for the Web-based management can change the system configuration to perform a command injection as root, resulting in a total loss of confidentiality, availability and integrity due to improper control of generation of code ('Code Injection').
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41699?
CVE-2025-41699 has a high severity level due to the potential for command injection and resulting compromise of confidentiality, availability, and integrity.
How do I fix CVE-2025-41699?
To fix CVE-2025-41699, ensure that the system is updated with the latest security patches provided by Phoenix Contact for the CHARX SEC-3xxx charging controllers.
What could happen if CVE-2025-41699 is exploited?
Exploitation of CVE-2025-41699 could lead to a complete compromise of the system, allowing an attacker to change configurations and execute commands with root privileges.
Who is affected by CVE-2025-41699?
CVE-2025-41699 affects users of the Phoenix Contact CHARX SEC-3xxx charging controllers that utilize web-based management interfaces.
Is authentication required to exploit CVE-2025-41699?
Yes, a low privileged remote attacker with an account for the web-based management is required to exploit CVE-2025-41699.