Phoenix Contact CHARX SEC-3000 Vulnerable to Sensitive Information Disclosure
A vulnerability in Phoenix Contact's CHARX SEC-3000 devices allows network-adjacent attackers to disclose sensitive information, including stored credentials, by exploiting a flaw in log file generation.
A critical information disclosure vulnerability has been identified in Phoenix Contact's CHARX SEC-3000 industrial control devices, allowing attackers to potentially gain access to sensitive credentials. The vulnerability, tracked as CVE-2026-41032, is present in the way log files are generated on the affected devices.
Network-adjacent attackers can exploit this flaw without requiring any authentication. The core of the issue lies in the inclusion of sensitive data within the device's log files. By accessing these logs, an attacker could retrieve stored credentials, which could then be used to facilitate further unauthorized access and compromise of the industrial control system.
The vulnerability carries a CVSS score of 6.5, indicating a moderate to high severity. This score reflects the potential impact of credential disclosure, which can lead to significant security breaches in critical infrastructure or industrial environments where these devices are deployed.
Phoenix Contact has acknowledged the vulnerability and has released an update to address the issue. Users of the CHARX SEC-3000 devices are strongly advised to apply the available patch as soon as possible to mitigate the risk of exploitation. Further details on the patch and its deployment can be found in advisories released by VDE (VDE-2026-060).
The vulnerability was initially reported to the vendor on April 16, 2026. Following a coordinated disclosure process, Zero Day Initiative (ZDI) published its advisory on July 30, 2026, bringing attention to the flaw and the availability of a fix. The disclosure timeline highlights the typical process of vulnerability discovery, vendor patching, and public notification.
This incident underscores the ongoing security challenges faced by manufacturers of industrial control systems (ICS) and operational technology (OT). As these devices become more interconnected, vulnerabilities that allow for information disclosure or credential theft pose a significant threat to the stability and security of critical infrastructure.
The researchers credited with discovering and reporting this vulnerability are Piotr Ptaszek and Mateusz Wójcik. Their work contributes to the broader effort of identifying and remediating security flaws in industrial hardware, helping to protect vital systems from cyber threats.
Organizations utilizing Phoenix Contact CHARX SEC-3000 devices should prioritize updating their systems to the latest firmware version. Regular security audits and prompt patching are essential practices for maintaining the integrity and security of industrial control environments against evolving cyber threats.