CVE-2026-44105: Phoenix Contact Charx Sec-3000

Medium severity, CVSS 6.6. EPSS: 0.1% chance of exploitation in the next 30 days.

The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.

Affected products

Published 2026-07-30. Last modified 2026-07-30.