ZDI-CAN-29054: ZDI-26-517: (Pwn2Own) Phoenix Contact CHARX SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44098.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29054?
The severity of ZDI-CAN-29054 is rated at 80, indicating a high risk vulnerability.
How do I fix ZDI-CAN-29054?
To fix ZDI-CAN-29054, apply any available security patches or updates from Phoenix Contact for the CHARX SEC-3150.
Who is affected by ZDI-CAN-29054?
Networks with Phoenix Contact CHARX SEC-3150 devices that have not been updated are affected by ZDI-CAN-29054.
What type of attack does ZDI-CAN-29054 permit?
ZDI-CAN-29054 allows attackers to execute arbitrary code via WebSocket command injection.
Is authentication required to exploit ZDI-CAN-29054?
Yes, authentication is required to exploit ZDI-CAN-29054, but the authentication mechanism can be bypassed.