ZDI-CAN-29110: ZDI-26-513: (Pwn2Own) Phoenix Contact CHARX SEC-3150 update2-upload Arbitrary File Upload Vulnerability
This vulnerability allows network-adjacent attackers to upload arbitrary files on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.4. The following CVEs are assigned: CVE-2026-44097.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29110?
ZDI-CAN-29110 has a CVSS rating of 2.4, indicating a low severity vulnerability.
How do I fix ZDI-CAN-29110?
To remediate ZDI-CAN-29110, update the Phoenix Contact CHARX SEC-3150 devices to the latest firmware that addresses this vulnerability.
What types of attacks does ZDI-CAN-29110 enable?
ZDI-CAN-29110 enables network-adjacent attackers to upload arbitrary files to the affected devices after successful authentication.
Is authentication required to exploit ZDI-CAN-29110?
Yes, authentication is required to exploit the vulnerability described in ZDI-CAN-29110.
Which device is affected by ZDI-CAN-29110?
The ZDI-CAN-29110 vulnerability affects the Phoenix Contact CHARX SEC-3150 device.