CVE-2026-44101: CWE-306 Missing Authentication for Critical Function in Phoenix Contact CHARX SEC-3150
CVE-2026-44101 is a critical vulnerability in Phoenix Contact CHARX SEC-3150 devices that allows network-adjacent attackers to modify device configuration without any authentication. This vulnerability is due to missing authentication for a critical function (CWE-306). It has a CVSS 4.0 base score of 9.3, indicating high impact and exploitability. No patch or official remediation is currently documented, and no known exploits in the wild have been reported.
AI Analysis
Technical Summary
CVE-2026-44101 affects Phoenix Contact CHARX SEC-3150 devices, where a critical function lacks authentication controls, enabling network-adjacent attackers to modify device configurations without credentials. The vulnerability is classified under CWE-306 (Missing Authentication for Critical Function). It has a CVSS 4.0 base score of 9.3, reflecting critical severity with network attack vector, low attack complexity, and no privileges or user interaction required. No official patch or remediation guidance is currently available from the vendor, and no active exploitation has been observed.
Potential Impact
An attacker with network adjacency can modify the device configuration without authentication, potentially leading to unauthorized changes that could disrupt device operation or compromise security. The high CVSS score (9.3) indicates a critical impact with high exploitability, but no known exploits have been reported in the wild.
Mitigation Recommendations
No patch or official remediation is currently documented for this vulnerability. Organizations using affected versions should monitor vendor advisories for updates. Until a fix is available, restricting network access to the device and implementing network segmentation may reduce exposure, but these are general mitigations and not vendor-specified.
CVE-2026-44101: CWE-306 Missing Authentication for Critical Function in Phoenix Contact CHARX SEC-3150
Description
CVE-2026-44101 is a critical vulnerability in Phoenix Contact CHARX SEC-3150 devices that allows network-adjacent attackers to modify device configuration without any authentication. This vulnerability is due to missing authentication for a critical function (CWE-306). It has a CVSS 4.0 base score of 9.3, indicating high impact and exploitability. No patch or official remediation is currently documented, and no known exploits in the wild have been reported.
CVSS v4.0
Score 9.3critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-44101 affects Phoenix Contact CHARX SEC-3150 devices, where a critical function lacks authentication controls, enabling network-adjacent attackers to modify device configurations without credentials. The vulnerability is classified under CWE-306 (Missing Authentication for Critical Function). It has a CVSS 4.0 base score of 9.3, reflecting critical severity with network attack vector, low attack complexity, and no privileges or user interaction required. No official patch or remediation guidance is currently available from the vendor, and no active exploitation has been observed.
Potential Impact
An attacker with network adjacency can modify the device configuration without authentication, potentially leading to unauthorized changes that could disrupt device operation or compromise security. The high CVSS score (9.3) indicates a critical impact with high exploitability, but no known exploits have been reported in the wild.
Mitigation Recommendations
No patch or official remediation is currently documented for this vulnerability. Organizations using affected versions should monitor vendor advisories for updates. Until a fix is available, restricting network access to the device and implementing network segmentation may reduce exposure, but these are general mitigations and not vendor-specified.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-xjm9-rr2c-vpq2
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-44101"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 4.0
Threat ID: 6a6b72b99c2644c7f84739a4
Added to database: 07/30/2026, 15:50:17 UTC
Last enriched: 08/15/2026, 05:13:30 UTC
Last updated: 09/13/2026, 22:01:34 UTC
Views: 80
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.