CVE-2024-28136: Phoenixcontact Charx Sec-3000 Firmware

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service.

Affected products

Published 2024-05-14. Last modified 2026-06-17.