A critical (CVSS 9.1) flaw in Phoenix Contact CHARX SEC charge controllers lets an unauthenticated remote attacker inject configuration entries via the MQTT broker, threatening the integrity and availability of EV charging infrastructure.
What Is It
CVE-2026-44091 is a trust-boundary violation (CWE-501) in the MQTT broker component of Phoenix Contact CHARX SEC charge controllers. An unauthenticated remote attacker can post a malicious ID to the MQTT broker, which results in the creation of a new configuration entry in the system configuration. The result is loss of integrity and availability.
The CVE was published 2026-07-30 and reported by CERT@VDE ([email protected]). NVD lists it in "Received" status, so enrichment is still pending.
Why It Matters
The CVSS v3.1 base score is 9.1 (CRITICAL), vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H. Every exploitability factor is at its worst setting: network-reachable, low attack complexity, no privileges, and no user interaction. Exploitability sub-score is a maximum 3.9.
CERT@VDE also assigned a CVSS v4.0 score of 8.8 (HIGH), with the same profile; network attack vector, no privileges required, no user interaction, high integrity and availability impact. Confidentiality impact is NONE in both scorings; this is a write/disrupt bug, not a data-theft bug.
Because the attacker writes into the system configuration of a charge controller, the practical exposure is unauthorized configuration changes and disruption of charging operations on any unit whose MQTT broker is reachable from an untrusted network.
What's Vulnerable
Phoenix Contact CHARX SEC controllers, versions 1.0.0 up to (but not including) 1.9.1:
- CHARX SEC-3000
- CHARX SEC-3050
- CHARX SEC-3100
- CHARX SEC-3150
Default status for these products is "unaffected" outside that range, so versions at or above 1.9.1 are not listed as affected.
Patch Status
The affected-version data indicates the issue is resolved in 1.9.1: that is the first version outside the affected range. No CISA KEV entry accompanies this CVE, so there is no evidence of active exploitation in the supplied data and no KEV-mandated remediation deadline. Consult the CERT@VDE advisory below for the vendor's official remediation guidance.
Sources
- NVD, CVE-2026-44091: https://nvd.nist.gov/vuln/detail/CVE-2026-44091
- CERT@VDE Advisory VDE-2026-008: https://www.certvde.com/en/advisories/VDE-2026-008/