Skip to main content

Vendor/product archive

phoenixcontact / charx_sec-3150 CVEs

Beta · best-effort

29 CVEs tagged to phoenixcontact / charx_sec-31502 Critical, 18 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2025-25271

Published Jul 8, 2025

An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-25270

Published Jul 8, 2025

An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-25269

Published Jul 8, 2025

An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-25268

Published Jul 8, 2025

An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-24006

Published Jul 8, 2025

A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-24005

Published Jul 8, 2025

A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-24004

Published Jul 8, 2025

A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a t…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-24003

Published Jul 8, 2025

An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integri…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-24002

Published Jul 8, 2025

An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-6788

Published Aug 13, 2024

A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” t…

CVSS 8.6 · High

CVE-2024-3913

Published Aug 13, 2024

An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.

CVSS 5.9 · Medium

CVE-2024-28136

Published May 14, 2024

A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service.

CVSS 7.8 · High

CVE-2024-28135

Published May 14, 2024

A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. T…

CVSS 5.0 · Medium

CVE-2024-28134

Published May 14, 2024

An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to c…

CVSS 7.0 · High

CVE-2024-26288

Published Mar 12, 2024

An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.

CVSS 8.7 · High

CVE-2024-26005

Published Mar 12, 2024

An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS.

CVSS 4.8 · Medium

CVE-2024-26004

Published Mar 12, 2024

An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality.

CVSS 7.5 · High

CVE-2024-26003

Published Mar 12, 2024

An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality.

CVSS 7.5 · High

CVE-2024-26002

Published Mar 12, 2024

An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files.

CVSS 7.8 · High

CVE-2024-26001

Published Mar 12, 2024

An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of me…

CVSS 7.4 · High

CVE-2024-26000

Published Mar 12, 2024

An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of mem…

CVSS 5.9 · Medium

CVE-2024-25999

Published Mar 12, 2024

An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service.

CVSS 8.4 · High

CVE-2024-25998

Published Mar 12, 2024

An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.

CVSS 7.3 · High
Showing 1-25 of 29 CVEsPage 1 of 2