SYS::ONLINE
Wasteland.
Briefs1616
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-44108 2026-07-30

CVE-2026-44108: Phoenix Contact CHARX EV Chargers Drop Their Firewall Mid-Shutdown

"A shutdown-sequence flaw in Phoenix Contact CHARX SEC charge controllers kills the firewall before the services it protects, briefly exposing internal services to unauthenticated remote attackers."

A shutdown-sequence flaw in Phoenix Contact CHARX SEC charge controllers kills the firewall before the services it protects, briefly exposing internal services to unauthenticated remote attackers.

What Is It

CVE-2026-44108 is a critical flaw (CVSS 3.1 base score 9.8, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; CVSS 4.0 base score 9.3) in Phoenix Contact CHARX SEC charge controllers, disclosed by CERT@VDE on 2026-07-30 as advisory VDE-2026-008.

The root cause is an incorrect execution order of scripts during system shutdown; classified as CWE-696 (Incorrect Behavior Order). The firewall terminates prematurely while the rest of the system is still winding down. That leaves a temporary window in which internal services, normally shielded from the network, become externally reachable. An unauthenticated remote attacker who connects during that window could achieve full system compromise.

Why It Matters

The attack requires no privileges, no user interaction, and no special conditions; just network reach and timing. Impact is High across confidentiality, integrity, and availability.

The practical wrinkle is the trigger: the exposure window opens on shutdown. That makes the flaw's real-world reachability a function of how often these devices restart; a figure the advisory and NVD record do not quantify, and one that will vary by operator. As an analytical inference rather than a sourced claim: any attacker able to observe or induce a device restart gets a repeatable shot at the window rather than a one-time accident. Operators are better positioned than the public record to judge how frequently that condition arises in their own fleets.

What's Vulnerable

Phoenix Contact CHARX SEC charge controllers, firmware versions 1.0.0 up to (but not including) 1.9.1:

Per the vendor-supplied affected-version data in the CVE record, all other versions are listed as unaffected.

Patch Status

Firmware 1.9.1 is the first fixed version; the affected range is explicitly bounded below 1.9.1. Operators of the four listed CHARX SEC models should upgrade to 1.9.1 or later and consult CERT@VDE advisory VDE-2026-008 for vendor-specific guidance.

CVE-2026-44108 does not appear in the CISA Known Exploited Vulnerabilities catalog, and no exploitation in the wild is confirmed in the supplied data. CVSS 4.0 exploit maturity is Not Defined. The NVD record was published 2026-07-30 and remains in "Received" status, so NVD-assigned analysis and CPE data are not yet available.

Sources