ZDI-26-508: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx_set_ip_address Improper Input Validation Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44095.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-508?
The severity of ZDI-26-508 is rated at 46, indicating a significant risk related to local privilege escalation.
How do I fix ZDI-26-508?
Fixing ZDI-26-508 requires applying the latest security patches provided by Phoenix Contact for the CHARX SEC-3150 device.
What type of vulnerability is ZDI-26-508?
ZDI-26-508 is an improper input validation vulnerability that can lead to local privilege escalation.
Who can exploit ZDI-26-508?
Only local attackers who have already gained the ability to execute low-privileged code on the system can exploit ZDI-26-508.
What product is affected by ZDI-26-508?
ZDI-26-508 affects the Phoenix Contact CHARX SEC-3150 device.