ZDI-CAN-29108: ZDI-26-508: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx_set_ip_address Improper Input Validation Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Phoenix Contact CHARX SEC-3150 devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-44095.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29108?
ZDI-CAN-29108 has a CVSS score of 46, indicating a significant risk due to its local privilege escalation potential.
How do I fix ZDI-CAN-29108?
To fix ZDI-CAN-29108, update the Phoenix Contact CHARX SEC-3150 to the latest firmware version provided by the vendor.
Who can exploit the ZDI-CAN-29108 vulnerability?
Only local attackers who have already obtained low-privileged code execution can exploit the ZDI-CAN-29108 vulnerability.
What are the consequences of exploiting ZDI-CAN-29108?
Exploiting ZDI-CAN-29108 can lead to a complete local privilege escalation on affected Phoenix Contact CHARX SEC-3150 devices.
Which software is affected by ZDI-CAN-29108?
The vulnerability ZDI-CAN-29108 affects the Phoenix Contact CHARX SEC-3150 devices.