CVE-2024-26000: Phoenixcontact Charx Sec-3000 Firmware
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.
Affected products
- Phoenixcontact Charx Sec-3000 Firmware: before 1.5.1 (fixed in 1.5.1)
- Phoenixcontact Charx Sec-3050 Firmware: before 1.5.1 (fixed in 1.5.1)
- Phoenixcontact Charx Sec-3100 Firmware: before 1.5.1 (fixed in 1.5.1)
- Phoenixcontact Charx Sec-3150 Firmware: before 1.5.1 (fixed in 1.5.1)
Published 2024-03-12. Last modified 2026-06-17.