CVE-2026-44094: Phoenix Contact Charx Sec-3000

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.

Affected products

Published 2026-07-30. Last modified 2026-07-30.