VYPR

Charx Sec 3000 Firmware

by Phoenixcontact

CVEs (29)

  • CVE-2024-3913MedAug 13, 2024
    risk 0.38cvss 5.9epss 0.01

    An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.

  • CVE-2024-26000MedMar 12, 2024
    risk 0.38cvss 5.9epss 0.01

    An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.

  • CVE-2024-25997MedMar 12, 2024
    risk 0.35cvss 5.3epss 0.01

    An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.

  • CVE-2024-25994MedMar 12, 2024
    risk 0.35cvss 5.3epss 0.01

    An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.

  • CVE-2025-24004MedJul 8, 2025
    risk 0.34cvss 5.2epss 0.00

    A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the stations until they got restarted by the watchdog.

  • CVE-2025-24002MedJul 8, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restarted by the watchdog.

  • CVE-2024-25996MedMar 12, 2024
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.

  • CVE-2024-28135MedMay 14, 2024
    risk 0.33cvss 5.0epss 0.01

    A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.

  • CVE-2024-26005MedMar 12, 2024
    risk 0.31cvss 4.8epss 0.01

    An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS. 

Page 2 of 2