Phoenix Contact CHARX SEC-3000
cpe:2.3:h:phoenixcontact:charx_sec-3000:*:*:*:*:*:*:*, +1 more
- <= 1.6.5
- < 1.7.3
A vulnerability exists in Phoenix Contact CHARX SEC-3xxx charging controllers, specifically in versions through 1.6.5 and prior to 1.7.3. This vulnerability allows low-privileged local attackers to exploit insecure SSH permissions on the affected devices, leading to unauthorized privilege escalation to root.
Exploitation of this vulnerability results in unauthorized root access on the affected device.
Users are advised to upgrade to firmware version 1.7.3, which addresses vulnerabilities CVE-2025-24005 and CVE-2025-24006. For general security recommendations, refer to the Phoenix Contact Application Note Security.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.