Phoenix Contact CHARX SEC-3150 Vulnerable to Arbitrary File Upload
A critical arbitrary file upload vulnerability has been discovered in Phoenix Contact's CHARX SEC-3150 devices, allowing authenticated attackers to upload arbitrary files.
A critical arbitrary file upload vulnerability has been identified in Phoenix Contact's CHARX SEC-3150 devices, a critical component often used in industrial control systems and power infrastructure. The vulnerability, tracked as ZDI-26-513 and assigned CVE-2026-44097, carries a CVSS score of 2.4, indicating a moderate severity, but its potential impact in industrial environments warrants attention.
The flaw resides within the update2-upload endpoint of the device's firmware. Attackers who have already gained authenticated access to the network can exploit this vulnerability by uploading arbitrary files to the affected system. This is possible due to a lack of proper validation of user-supplied data within the upload process, allowing malicious files to be placed on the device.
While the CVSS score is low, the ability to upload arbitrary files can serve as a stepping stone for more severe attacks. An attacker could potentially upload malicious scripts, configuration files, or even backdoors that could lead to further compromise of the device or the network it resides on. The requirement for authentication means that initial network access and credentials are prerequisites for exploitation.
The vulnerability was discovered by a team of researchers from BoB::Takedown, including Hyeongseok Lee, Yunje Shin, Chaeeul Hyun, Ingyu Yang, Hoseok Kang, Seungyeon Park, and Wonjun Choi. The Zero Day Initiative (ZDI) coordinated the disclosure process, with the vulnerability being reported to the vendor on February 9, 2026, and publicly disclosed on July 30, 2026.
Phoenix Contact has addressed the vulnerability by releasing firmware version 1.9.1. Users are strongly advised to update their CHARX SEC-3150 devices to this latest firmware as soon as possible. The update is expected to be available by August 12, 2026. Further details and advisories can be found through VDE CERT under advisory VDE-2026-008.
This discovery follows other recent vulnerabilities found in Phoenix Contact devices, highlighting a potential area of concern for organizations relying on their industrial hardware. Users should remain vigilant and ensure all devices are kept up-to-date with the latest security patches.
The disclosure timeline indicates a relatively swift response from the vendor after the vulnerability was reported, which is a positive sign for the security of industrial control systems. However, the extended period between the initial report and public disclosure underscores the complexities of securing specialized hardware.
Organizations utilizing Phoenix Contact CHARX SEC-3150 devices should prioritize applying the available firmware update to mitigate the risk of arbitrary file uploads and potential subsequent system compromise. Regular security audits and monitoring for unauthorized file activity on these devices are also recommended.
This advisory details a separate vulnerability, CVE-2026-44100, affecting Phoenix Contact's CHARX SEC-3150 devices. Unlike the previously reported arbitrary file upload flaw, this new issue allows network-adjacent attackers to modify device configurations without any authentication, exploiting a flaw in the charx-jupicore REST API. The vulnerability has a CVSS score of 4.2 and is expected to be fixed in firmware v1.9.1 by August 12, 2026.
This advisory details a critical authentication bypass vulnerability (CVE-2026-44094) in Phoenix Contact's CHARX SEC-3150 devices, allowing network-adjacent attackers to bypass authentication without credentials. The Zero Day Initiative assigned this vulnerability a CVSS score of 7.5. A fix is expected in firmware v1.9.1 by August 12, 2026.