SYS::ONLINE
Wasteland.
Briefs1616
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-7849 2026-07-30

Phoenix Contact CHARX EV Chargers: Unauthenticated Root Command Injection (CVE-2026-7849)

"A critical command injection flaw in Phoenix Contact CHARX SEC charge controllers lets an unauthenticated remote attacker execute commands as root, rated CVSS 9.8."

A critical command injection flaw in Phoenix Contact CHARX SEC charge controllers lets an unauthenticated remote attacker execute commands as root, rated CVSS 9.8.

What Is It

CVE-2026-7849 is an improper neutralization of special elements (CWE-77) in Phoenix Contact CHARX SEC charge controllers. Per the NVD record, an unauthenticated remote attacker can inject a command into the system configuration, which is subsequently executed as root.

The flaw carries a CVSS v3.1 base score of 9.8 (CRITICAL): vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. A secondary CVSS v4.0 score from the reporting CNA rates it 9.3 (CRITICAL). The CVE was published 2026-07-30 by CERT@VDE and currently sits in NVD Received status.

Why It Matters

Every barrier that normally slows an attacker is absent here: network attack vector, low attack complexity, no privileges required, and no user interaction. Confidentiality, integrity, and availability impacts are all rated HIGH, consistent with code execution at root on the device.

Because the injected command lands in the system configuration and executes as root, a successful attack means full control of the charge controller, not a partial compromise.

CVE-2026-7849 does not appear in the CISA Known Exploited Vulnerabilities catalog (linked in Sources) as of publication, so active exploitation is not confirmed by KEV at this time. That is not evidence of safety; the CVE is under a day old and NVD analysis is incomplete. Readers can verify current KEV status directly against the catalog, which CISA updates on a rolling basis.

What's Vulnerable

Phoenix Contact CHARX SEC charge controllers, versions 1.0.0 up to (but not including) 1.9.1:

All four products share the same affected range. Versions outside that range are listed as unaffected by the vendor. No affected CPE entries were present in the NVD record.

Patch Status

The version data indicates 1.9.1 is the fixed release: the affected range terminates below it for all four products. Operators of SEC-3000/3050/3100/3150 should upgrade to 1.9.1 or later.

Because the CVE is absent from the CISA KEV catalog (see Sources), there is no KEV-mandated remediation deadline or required action attached to it for federal civilian agencies under BOD 22-01. Refer to the CERT@VDE advisory below for vendor remediation guidance and any workarounds.

Sources