ZDI-26-509: (Pwn2Own) Phoenix Contact CHARX SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to modify configuration on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-44101.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-509?
The severity of ZDI-26-509 is rated with a CVSS score of 5.0.
How do I fix ZDI-26-509?
To fix ZDI-26-509, update the Phoenix Contact CHARX SEC-3150 device firmware to the latest version that addresses the vulnerability.
Who is affected by ZDI-26-509?
Organizations using Phoenix Contact CHARX SEC-3150 devices are affected by ZDI-26-509.
What type of vulnerability is ZDI-26-509?
ZDI-26-509 is an authentication bypass vulnerability that allows unauthorized access to critical functions.
What can attackers do with ZDI-26-509?
Attackers exploiting ZDI-26-509 can modify configurations on affected Phoenix Contact CHARX SEC-3150 installations without authentication.