A missing authentication flaw in the CHARX OCPP Agent service lets an unauthenticated remote attacker reconfigure the charging station's backend connection, enabling denial-of-service and disclosure of confidential data.
What Is It
CVE-2026-44101 is a missing-authentication vulnerability (CWE-306) in the CHARX OCPP Agent service on Phoenix Contact CHARX SEC electric vehicle charging controllers. The OCPP Agent handles the station's connection to its backend management system. Because the service does not authenticate requests, a remote attacker can reach it and reconfigure that backend connection without any credentials.
Two consequences follow directly from that reconfiguration: the charging station can be cut off from its legitimate backend, causing a denial-of-service, and traffic or configuration data can be redirected such that confidential data is disclosed to the attacker.
The CVE was published 2026-07-30 by CERT@VDE and is currently in "Received" status at NVD.
Why It Matters
The flaw is rated CVSS 3.1 base score 9.8 (CRITICAL): vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Attack vector is network, attack complexity is low, and no privileges or user interaction are required. Confidentiality, integrity, and availability impacts are all rated High. CERT@VDE also supplied a CVSS 4.0 score of 9.3 (Critical).
In practical terms, that combination means there is no meaningful barrier between a network-reachable CHARX controller and an attacker able to seize its backend configuration. Exploit maturity is not defined in the record.
What's Vulnerable
Phoenix Contact products affected, all versions from 1.0.0 up to (but not including) 1.9.1:
- CHARX SEC-3000
- CHARX SEC-3050
- CHARX SEC-3100
- CHARX SEC-3150
Versions outside that range are listed as unaffected. No affected CPEs are enumerated in the NVD record.
Patch Status
The affected version ranges end at 1.9.1, indicating that 1.9.1 and later are not affected; operators should move CHARX SEC-3000/3050/3100/3150 devices to firmware 1.9.1 or newer. Consult the CERT@VDE advisory VDE-2026-008 for vendor remediation guidance.
No CISA Known Exploited Vulnerabilities entry accompanied this record at the time of writing, so there is no confirmation of active exploitation and no KEV-mandated required action or due date. Operators should check the KEV catalog directly for the current status.
Sources
- NVD, CVE-2026-44101: https://nvd.nist.gov/vuln/detail/CVE-2026-44101
- CERT@VDE Advisory VDE-2026-008: https://www.certvde.com/en/advisories/VDE-2026-008/
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog