ZDI-26-521: Phoenix Contact CHARX SEC-3000 Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44095.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Limit network adjacency to Phoenix Contact CHARX SEC-3000 devices (reduce exposure to network-adjacent attackers)
- Compensating control
Require authentication for access to the CHARX SEC-3000 interfaces/services to reduce likelihood of command injection exploitation
- Compensating control
Monitor for and block exploitation attempts related to ZDI-26-521 on network paths to Phoenix Contact CHARX SEC-3000 devices (e.g., via firewall/WAF rules)
Event History
Frequently Asked Questions
What is the severity of ZDI-26-521?
The severity of ZDI-26-521 is rated at 6.8 according to the CVSS framework.
How do I fix ZDI-26-521?
To fix ZDI-26-521, ensure that your Phoenix Contact CHARX SEC-3000 devices are updated to the latest firmware release provided by the vendor.
Who is affected by ZDI-26-521?
ZDI-26-521 affects installations of Phoenix Contact CHARX SEC-3000 devices that allow network-adjacent access.
What could an attacker achieve by exploiting ZDI-26-521?
An attacker could execute arbitrary code on the affected Phoenix Contact CHARX SEC-3000 devices.
Is authentication required to exploit ZDI-26-521?
Yes, authentication is required to exploit the ZDI-26-521 vulnerability.