CVE-2026-44104: Phoenix Contact Charx Sec-3000

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.

Affected products

Published 2026-07-30. Last modified 2026-07-30.