ZDI-CAN-29093: ZDI-26-520: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-44103.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29093?
The vulnerability ZDI-CAN-29093 has a CVSS score of 7.5, indicating it is of high severity.
How do I fix ZDI-CAN-29093?
To mitigate ZDI-CAN-29093, update the firmware of your Phoenix Contact CHARX SEC-3150 devices to the latest version provided by the vendor.
Who is affected by ZDI-CAN-29093?
Any installations of Phoenix Contact CHARX SEC-3150 devices are affected by the vulnerability ZDI-CAN-29093.
Can ZDI-CAN-29093 be exploited remotely?
Yes, ZDI-CAN-29093 allows network-adjacent attackers to exploit the vulnerability without requiring authentication.
What type of vulnerability is ZDI-CAN-29093?
ZDI-CAN-29093 is categorized as a remote code execution vulnerability.