ZDI-26-503: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Race Condition Firewall Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-44108.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-503?
The CVSS rating of ZDI-26-503 is 6.4, indicating a medium level of risk.
How do I fix ZDI-26-503?
To mitigate ZDI-26-503, ensure that you apply the latest firmware updates provided by Phoenix Contact for the CHARX SEC-3150.
Who is affected by ZDI-26-503?
ZDI-26-503 affects installations of Phoenix Contact CHARX SEC-3150 devices.
Can ZDI-26-503 be exploited without authentication?
Yes, ZDI-26-503 can be exploited without authentication, allowing network-adjacent attackers to bypass firewall rules.
What type of vulnerability is ZDI-26-503?
ZDI-26-503 is a race condition vulnerability that allows for a firewall bypass in affected devices.