Phoenix Contact CHARX SEC-3150 MQTT Service Vulnerable to SSRF and RCE
A Server-Side Request Forgery (SSRF) vulnerability in Phoenix Contact's CHARX SEC-3150 MQTT service allows network-adjacent attackers to access internal resources and potentially execute code.
Zero Day Initiative (ZDI) has disclosed a critical Server-Side Request Forgery (SSRF) vulnerability affecting the MQTT service on Phoenix Contact's CHARX SEC-3150 devices. The vulnerability, tracked as ZDI-26-518 and assigned CVE-2026-44091, carries a CVSS score of 6.3 and allows network-adjacent attackers to access internal resources without requiring any form of authentication.
The core of the issue lies in the MQTT service's inadequate validation of Uniform Resource Identifiers (URIs) before accessing resources. This oversight enables an attacker to manipulate the service into making requests to internal network locations that would otherwise be inaccessible. By exploiting this SSRF flaw, attackers can potentially chain it with other vulnerabilities to achieve arbitrary code execution within the context of the 'user-app' account on the affected devices.
This vulnerability was discovered by Giuseppe Calì, who reported it to the vendor on February 9, 2026. The coordinated public release of the advisory occurred on July 30, 2026, with an update to the advisory also published on the same date. The disclosure timeline indicates a proactive approach to security patching and communication between ZDI and Phoenix Contact.
Phoenix Contact has addressed this vulnerability by releasing firmware version v1.9.1. Users are advised to update their devices to this latest version to mitigate the risk. The updated firmware is expected to be available by August 12, 2026, according to information provided by CERT VDE (advisory VDE-2026-008).
The CHARX SEC-3150 is a component often found in industrial control systems and critical infrastructure, making vulnerabilities like this particularly concerning. The ability for an attacker to access internal resources and potentially execute code remotely could lead to significant operational disruptions, data breaches, or even physical damage, depending on the system's role.
This disclosure adds to a growing list of security concerns surrounding industrial control system (ICS) components. As these devices become more interconnected, the attack surface expands, necessitating continuous vigilance and prompt patching by manufacturers and operators alike. The SSRF vulnerability, in particular, highlights the importance of strict input validation, especially when dealing with network requests originating from untrusted sources or user-controlled data.
While the CVSS score of 6.3 indicates a moderate-to-high severity, the potential for chaining this SSRF vulnerability with other flaws to achieve remote code execution elevates its practical risk. Organizations utilizing Phoenix Contact CHARX SEC-3150 devices should prioritize applying the available firmware update to protect their networks and operations from potential exploitation.
The Zero Day Initiative has disclosed a new critical vulnerability, ZDI-26-519, affecting Phoenix Contact's CHARX SEC-3150 devices. This flaw, identified as a configuration injection vulnerability in the CharxSystemConfigManager service, allows network-adjacent attackers to achieve remote code execution without authentication. The vulnerability has been assigned a CVSS score of 7.5 and is fixed in firmware version v1.9.1, with an update expected by August 12, 2026.
This new advisory details a separate critical vulnerability, CVE-2026-44103, affecting Phoenix Contact's CHARX SEC-3150 Jupicore devices. Unlike the previously reported SSRF and RCE flaws in the MQTT service, this vulnerability allows unauthenticated, network-adjacent attackers to achieve remote code execution by exploiting improper validation in the firmware-update endpoint. The Zero Day Initiative has assigned this flaw a CVSS score of 7.5, indicating a significant risk to industrial control systems.
This new advisory from Zero Day Initiative details a separate command injection vulnerability (CVE-2026-44095) affecting Phoenix Contact CHARX SEC-3000 devices, distinct from the previously reported SSRF and RCE flaws in the CHARX SEC-3150's MQTT service. The vulnerability allows network-adjacent attackers with authentication to achieve remote code execution by exploiting improper validation of the defaultroutemetric parameter, leading to arbitrary code execution in the context of root.
This new advisory details a separate configuration injection vulnerability, CVE-2026-7849, affecting the CharxSystemConfigManager service on Phoenix Contact CHARX SEC-3150 devices. Unlike the previously reported SSRF flaw, this vulnerability allows network-adjacent attackers to achieve remote code execution without authentication by exploiting improper validation of configuration strings. The Zero Day Initiative has assigned this flaw a CVSS score of 7.5.
This new advisory details a CRLF injection vulnerability (CVE-2026-44092) in the charx-system-config-manager service of Phoenix Contact CHARX SEC-3150 devices, which allows network-adjacent attackers to bypass firewall rules. The flaw, demonstrated at Pwn2Own and carrying a CVSS score of 5.0, does not require authentication and can be leveraged to execute code in the context of the user-app user, adding another attack vector to the previously reported SSRF and RCE flaws in the device's MQTT service.