Phoenix Contact CHARX SEC-3150 Vulnerable to Privilege Escalation via Sudo Rule Flaw
A local privilege escalation vulnerability, CVE-2026-44096, has been discovered in Phoenix Contact CHARX SEC-3150 devices, allowing attackers with low-privilege code execution to gain root access.
Security researchers have identified a critical local privilege escalation vulnerability, tracked as CVE-2026-44096, affecting Phoenix Contact's CHARX SEC-3150 devices. This flaw, disclosed by the Zero Day Initiative (ZDI), allows an attacker who has already gained the ability to execute low-privileged code on a target system to elevate their privileges to that of root.
The vulnerability stems from an insecure configuration within the device's sudo rules. Specifically, the system permits the privileged execution of a binary that, due to its nature or how it's handled, can be manipulated to perform unsafe actions. By exploiting this misconfiguration, an attacker can bypass intended security restrictions and achieve arbitrary code execution with the highest level of system access.
The Zero Day Initiative has assigned a CVSS score of 7.8 to this vulnerability, indicating a high severity. This score reflects the potential for significant impact on affected systems, particularly in environments where unauthorized root access could lead to data breaches, system disruption, or further network compromise.
Phoenix Contact has addressed this vulnerability by releasing firmware version v1.9.1. Users are strongly advised to update their CHARX SEC-3150 devices to this latest firmware as soon as possible. The updated firmware was made available by August 12, 2026, and further details can be found in advisories from CERT VDE (VDE-2026-008).
The vulnerability was initially reported to the vendor on February 9, 2026. Following a coordinated disclosure process, the Zero Day Initiative published its advisory on July 30, 2026, with an update to the advisory also occurring on the same date. This timeline highlights the typical process of vulnerability discovery, vendor patching, and public disclosure aimed at informing users and security professionals.
This discovery was made by a team of researchers from BoB::Takedown, including Hyeongseok Lee, Yunje Shin, Chaeeul Hyun, Ingyu Yang, Hoseok Kang, Seungyeon Park, and Wonjun Choi. Their collective efforts in identifying and reporting such vulnerabilities contribute significantly to the overall security posture of industrial control systems and connected devices.
The CHARX SEC-3150 is a component often found in industrial and energy sectors, making privilege escalation vulnerabilities particularly concerning. Gaining root access could allow an attacker to manipulate critical operational parameters, disrupt services, or exfiltrate sensitive operational data, underscoring the importance of timely patching and robust security practices for such devices.
This new advisory, ZDI-26-506, details a distinct authentication bypass vulnerability (CVE-2026-44105) in Phoenix Contact CHARX SEC-3150 devices, separate from the previously reported privilege escalation flaw. Unlike the local privilege escalation, this new vulnerability allows network-adjacent attackers to bypass authentication entirely without needing credentials, stemming from the improper inclusion of sensitive information in log files.
This new advisory from the Zero Day Initiative details a separate authentication bypass vulnerability, ZDI-26-509 (CVE-2026-44101), affecting the same Phoenix Contact CHARX SEC-3150 devices. Unlike the previously reported privilege escalation flaw, this vulnerability allows network-adjacent attackers to modify device configurations by exploiting a missing authentication check in the export-import endpoint, carrying a CVSS score of 5.0.
This new advisory details a separate local privilege escalation vulnerability, CVE-2026-44095, within the charx_set_ip_address binary of the Phoenix Contact CHARX SEC-3150. Unlike the previously reported sudo rule flaw (CVE-2026-44096), this vulnerability stems from improper input validation and also requires initial low-privileged code execution to achieve root privileges. The fix is expected in firmware v1.9.1 by August 12, 2026.
This new advisory details a critical remote code execution vulnerability (CVE-2026-44104) in the same Phoenix Contact CHARX SEC-3150 devices, distinct from the previously reported privilege escalation flaw. The RCE vulnerability allows network-adjacent attackers to bypass firmware validation and execute arbitrary code without authentication, carrying a CVSS score of 7.5. A fix is expected in firmware v1.9.1 by August 12, 2026.
This new advisory, ZDI-26-511, details a separate local privilege escalation vulnerability (CVE-2026-44093) in Phoenix Contact CHARX SEC-3150 devices, distinct from the previously reported sudo rule flaw (CVE-2026-44096). The newly disclosed vulnerability stems from a symlink following flaw within the user-applications component, requiring prior low-privileged code execution to exploit and carrying a CVSS score of 7.8. A fix is expected in firmware v1.9.1 by August 12, 2026.
This new advisory details a separate denial-of-service vulnerability (CVE-2026-44107) affecting the same Phoenix Contact CHARX SEC-3150 devices. Unlike the privilege escalation flaw, this DoS vulnerability can be exploited by network-adjacent attackers without authentication, targeting the ModBus server on port 502. The vulnerability has been fixed in firmware v1.9.1, expected by August 12, 2026.
This new advisory from Zero Day Initiative details a different local privilege escalation vulnerability (CVE-2026-44106) in Phoenix Contact CHARX SEC-3150 devices, distinct from the previously reported sudo rule flaw (CVE-2026-44096). The ZDI vulnerability stems from an issue within the user-applications script that allows arbitrary file manipulation via symbolic links, enabling attackers to achieve root privileges. This flaw was demonstrated at Pwn2Own and has a CVSS score of 7.8, with a fix expected in firmware v1.9.1 by August 12, 2026.
This advisory details a separate critical vulnerability, ZDI-26-517, affecting Phoenix Contact's CHARX SEC-3150 devices. Unlike the previously reported privilege escalation flaw, this new vulnerability allows network-adjacent attackers to achieve remote code execution by exploiting a backend URL WebSocket command injection flaw. While authentication is required, the vulnerability can bypass existing mechanisms by leveraging improper validation of user-supplied strings in log file handling, leading to code execution in the context of the charx-oa account.
This new advisory from Zero Day Initiative details a distinct race condition vulnerability (CVE-2026-44108) in Phoenix Contact CHARX SEC-3150 devices, which allows network-adjacent attackers to bypass firewall rules without authentication. While the previously reported privilege escalation flaw (CVE-2026-44096) required low-privilege code execution to achieve root access, this new vulnerability targets firewall rule handling during device shutdown and has a CVSS score of 6.4. A firmware update, v1.9.1, is expected by August 12, 2026, to address this issue.