CVE-2024-6788: Phoenixcontact Charx Sec-3000 Firmware

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.

Affected products

Published 2024-08-13. Last modified 2026-06-17.