ZDI-CAN-27763: ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability
Published Jul 30, 2026
·Updated
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-41032.
Affected Software
1 affected component
Phoenix Contact CHARX SEC-3000
Event History
Jul 30, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-27763?
The severity of ZDI-CAN-27763 is rated at 6.5 according to the CVSS scale.
2
How do I fix ZDI-CAN-27763?
To mitigate ZDI-CAN-27763, apply any patches provided by Phoenix Contact for the CHARX SEC-3000 devices.
3
What kind of information can be disclosed due to ZDI-CAN-27763?
ZDI-CAN-27763 allows the disclosure of sensitive information stored in log files of affected CHARX SEC-3000 devices.
4
Is authentication required to exploit ZDI-CAN-27763?
No, authentication is not required to exploit ZDI-CAN-27763.
5
Which devices are affected by ZDI-CAN-27763?
The ZDI-CAN-27763 vulnerability affects the Phoenix Contact CHARX SEC-3000 devices.