ZDI-CAN-29091: ZDI-26-509: (Pwn2Own) Phoenix Contact CHARX SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to modify configuration on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-44101.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29091?
The severity of ZDI-CAN-29091 is rated at 5.0 according to the CVSS scale.
How do I fix ZDI-CAN-29091?
To fix ZDI-CAN-29091, you need to apply available security patches provided by Phoenix Contact.
What devices are affected by ZDI-CAN-29091?
The devices affected by ZDI-CAN-29091 are the Phoenix Contact CHARX SEC-3150.
What type of vulnerability is ZDI-CAN-29091?
ZDI-CAN-29091 is an authentication bypass vulnerability that allows attackers to modify configurations.
Can ZDI-CAN-29091 be exploited remotely?
Yes, ZDI-CAN-29091 can be exploited by network-adjacent attackers without the need for authentication.