CVE-2026-41032: Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers
Published Jun 3, 2026
·Updated
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
Affected Software
1 affected component
Phoenix Contact CHARX SEC-3xxx charging controller firmware
Event History
Jun 3, 2026
CVE Published
via MITRE·10:16 AM
Data Sourced
via MITRE·10:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-41032?
The severity of CVE-2026-41032 is high, with a score of 7.5.
2
How do I fix CVE-2026-41032?
To mitigate CVE-2026-41032, ensure that firmware updates from Phoenix Contact are applied promptly.
3
What type of vulnerability is CVE-2026-41032?
CVE-2026-41032 is an unauthenticated log download vulnerability resulting in potential information leakage.
4
Who is affected by CVE-2026-41032?
Users of the Phoenix Contact CHARX SEC-3xxx charging controller firmware are affected by CVE-2026-41032.
5
What could be the impact of CVE-2026-41032?
CVE-2026-41032 could allow adjacent attackers to download sensitive log files, potentially disclosing restricted information.