SYS::ONLINE
Wasteland.
Briefs1616
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-44101 2026-07-30

Phoenix Contact CHARX EV Chargers: Unauthenticated Backend Takeover (CVE-2026-44101)

"A missing authentication flaw in the CHARX OCPP Agent service lets an unauthenticated remote attacker reconfigure the charging station's backend connection, enabling denial-of-service and disclosure of confidential data."

A missing authentication flaw in the CHARX OCPP Agent service lets an unauthenticated remote attacker reconfigure the charging station's backend connection, enabling denial-of-service and disclosure of confidential data.

What Is It

CVE-2026-44101 is a missing-authentication vulnerability (CWE-306) in the CHARX OCPP Agent service on Phoenix Contact CHARX SEC electric vehicle charging controllers. The OCPP Agent handles the station's connection to its backend management system. Because the service does not authenticate requests, a remote attacker can reach it and reconfigure that backend connection without any credentials.

Two consequences follow directly from that reconfiguration: the charging station can be cut off from its legitimate backend, causing a denial-of-service, and traffic or configuration data can be redirected such that confidential data is disclosed to the attacker.

The CVE was published 2026-07-30 by CERT@VDE and is currently in "Received" status at NVD.

Why It Matters

The flaw is rated CVSS 3.1 base score 9.8 (CRITICAL): vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Attack vector is network, attack complexity is low, and no privileges or user interaction are required. Confidentiality, integrity, and availability impacts are all rated High. CERT@VDE also supplied a CVSS 4.0 score of 9.3 (Critical).

In practical terms, that combination means there is no meaningful barrier between a network-reachable CHARX controller and an attacker able to seize its backend configuration. Exploit maturity is not defined in the record.

What's Vulnerable

Phoenix Contact products affected, all versions from 1.0.0 up to (but not including) 1.9.1:

Versions outside that range are listed as unaffected. No affected CPEs are enumerated in the NVD record.

Patch Status

The affected version ranges end at 1.9.1, indicating that 1.9.1 and later are not affected; operators should move CHARX SEC-3000/3050/3100/3150 devices to firmware 1.9.1 or newer. Consult the CERT@VDE advisory VDE-2026-008 for vendor remediation guidance.

No CISA Known Exploited Vulnerabilities entry accompanied this record at the time of writing, so there is no confirmation of active exploitation and no KEV-mandated required action or due date. Operators should check the KEV catalog directly for the current status.

Sources