SYS::ONLINE
Wasteland.
Briefs1616
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-44091 2026-07-30

CVE-2026-44091: Unauthenticated MQTT Config Injection in Phoenix Contact CHARX EV Chargers

"A critical (CVSS 9.1) flaw in Phoenix Contact CHARX SEC charge controllers lets an unauthenticated remote attacker inject configuration entries via the MQTT broker, threatening the integrity and availability of EV…"

A critical (CVSS 9.1) flaw in Phoenix Contact CHARX SEC charge controllers lets an unauthenticated remote attacker inject configuration entries via the MQTT broker, threatening the integrity and availability of EV charging infrastructure.

What Is It

CVE-2026-44091 is a trust-boundary violation (CWE-501) in the MQTT broker component of Phoenix Contact CHARX SEC charge controllers. An unauthenticated remote attacker can post a malicious ID to the MQTT broker, which results in the creation of a new configuration entry in the system configuration. The result is loss of integrity and availability.

The CVE was published 2026-07-30 and reported by CERT@VDE ([email protected]). NVD lists it in "Received" status, so enrichment is still pending.

Why It Matters

The CVSS v3.1 base score is 9.1 (CRITICAL), vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H. Every exploitability factor is at its worst setting: network-reachable, low attack complexity, no privileges, and no user interaction. Exploitability sub-score is a maximum 3.9.

CERT@VDE also assigned a CVSS v4.0 score of 8.8 (HIGH), with the same profile; network attack vector, no privileges required, no user interaction, high integrity and availability impact. Confidentiality impact is NONE in both scorings; this is a write/disrupt bug, not a data-theft bug.

Because the attacker writes into the system configuration of a charge controller, the practical exposure is unauthorized configuration changes and disruption of charging operations on any unit whose MQTT broker is reachable from an untrusted network.

What's Vulnerable

Phoenix Contact CHARX SEC controllers, versions 1.0.0 up to (but not including) 1.9.1:

Default status for these products is "unaffected" outside that range, so versions at or above 1.9.1 are not listed as affected.

Patch Status

The affected-version data indicates the issue is resolved in 1.9.1: that is the first version outside the affected range. No CISA KEV entry accompanies this CVE, so there is no evidence of active exploitation in the supplied data and no KEV-mandated remediation deadline. Consult the CERT@VDE advisory below for the vendor's official remediation guidance.

Sources