ZDI-26-515: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability
This vulnerability allows network-adjacent attackers to modify configuration on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.2. The following CVEs are assigned: CVE-2026-44100.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-515?
The ZDI-26-515 vulnerability has a CVSS rating of 4.2, indicating a medium severity level.
How do I fix ZDI-26-515?
To mitigate the ZDI-26-515 vulnerability, ensure proper authentication mechanisms are implemented on affected Phoenix Contact CHARX SEC-3150 devices.
What type of attacker can exploit ZDI-26-515?
Network-adjacent attackers can exploit the ZDI-26-515 vulnerability due to the lack of required authentication.
What devices are affected by ZDI-26-515?
The Phoenix Contact CHARX SEC-3150 devices are affected by the ZDI-26-515 vulnerability.
What is the nature of the ZDI-26-515 vulnerability?
ZDI-26-515 is a missing authentication configuration modification vulnerability that allows attackers to alter device configurations.