ZDI-26-513: (Pwn2Own) Phoenix Contact CHARX SEC-3150 update2-upload Arbitrary File Upload Vulnerability
This vulnerability allows network-adjacent attackers to upload arbitrary files on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.4. The following CVEs are assigned: CVE-2026-44097.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-513?
The severity of ZDI-26-513 is rated at a CVSS score of 2.4.
What does the ZDI-26-513 vulnerability allow an attacker to do?
ZDI-26-513 allows network-adjacent attackers to upload arbitrary files on affected Phoenix Contact CHARX SEC-3150 devices.
Is authentication required to exploit ZDI-26-513?
Yes, authentication is required to exploit the ZDI-26-513 vulnerability.
What devices are affected by ZDI-26-513?
The vulnerability affects installations of the Phoenix Contact CHARX SEC-3150 devices.
How can ZDI-26-513 be mitigated?
Mitigation strategies for ZDI-26-513 include applying the latest firmware updates and restricting access to authorized users.