ZDI-26-517: (Pwn2Own) Phoenix Contact CHARX SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44098.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-517?
The severity of ZDI-26-517 is rated 80, indicating a high level of risk.
How do I fix ZDI-26-517?
To fix ZDI-26-517, you should update the Phoenix Contact CHARX SEC-3150 devices to the latest firmware as provided by the vendor.
What type of attack is facilitated by ZDI-26-517?
ZDI-26-517 facilitates remote code execution through WebSocket command injection.
Who is affected by ZDI-26-517?
Devices running the Phoenix Contact CHARX SEC-3150 software are affected by ZDI-26-517.
Does ZDI-26-517 require authentication to exploit?
Yes, ZDI-26-517 requires authentication to exploit, but the existing authentication mechanism can be bypassed.