CVE-2024-6788: Phoenixcontact Charx Sec-3000 Firmware
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.
Affected products
- Phoenixcontact Charx Sec-3000 Firmware: before 1.6.3 (fixed in 1.6.3)
- Phoenixcontact Charx Sec-3050 Firmware: before 1.6.3 (fixed in 1.6.3)
- Phoenixcontact Charx Sec-3100 Firmware: before 1.6.3 (fixed in 1.6.3)
- Phoenixcontact Charx Sec-3150 Firmware: before 1.6.3 (fixed in 1.6.3)
Published 2024-08-13. Last modified 2026-06-17.