Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/phoenixcontact/CHARX-SEC-3150

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-44107 is a high-severity vulnerability in the Phoenix Contact CHARX SEC-3150 charging controller version 1.0.0. It allows an unauthenticated attacker to cause a denial-of-service by triggering a device reboot via Modbus TCP when the Modbus service is enabled. This disrupts the normal operation of the charging controller.

Join the discussion

CVE-2026-44100 is a high-severity vulnerability affecting the Phoenix Contact CHARX SEC-3150 device, specifically version 1.0.0. The vulnerability arises from the CHARX JupiCore service lacking authentication for critical functions, which allows unauthenticated remote attackers to reconfigure charging points. Exploitation can lead to disclosure of unique identifiers (UIDs) of charging points, denial-of-service conditions, and tampering with device files.

Join the discussion

CVE-2026-44098 is a high-severity vulnerability in Phoenix Contact CHARX SEC-3150 devices that allows network-adjacent attackers to execute arbitrary code. The vulnerability involves improper neutralization of special elements in OS commands (CWE-78), enabling OS command injection. Exploitation requires authentication, but the authentication mechanism can be bypassed. The CVSS 4.0 base score is 8.8, indicating a significant risk. No official patch or remediation guidance is currently available.

Join the discussion

CVE-2026-44097 is a medium severity vulnerability in Phoenix Contact CHARX SEC-3150 version 1.0.0. It allows a low-privileged remote attacker with operator access to upload arbitrary files through a REST endpoint intended for firmware updates. This unrestricted file upload can lead to persistent storage of attacker-controlled files, potentially causing resource exhaustion and denial-of-service conditions.

Join the discussion

A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation.

Join the discussion

A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the stations until they got restarted by the watchdog.

Join the discussion

An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only EichrechtAgents and potential denial-of-service for these stations.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:github/phoenixcontact/CHARX-SEC-3150
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses