CVE-2024-25994: Phoenixcontact Charx Sec-3000 Firmware

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.

Affected products

Published 2024-03-12. Last modified 2026-06-17.