Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-44107: CWE-749 Exposed Dangerous Method or Function in Phoenix Contact CHARX SEC-3150CVE-2026-44107
0

CVE-2026-44107 is a high-severity vulnerability in the Phoenix Contact CHARX SEC-3150 charging controller. It allows an unauthenticated attacker to trigger a reboot of the device via Modbus TCP when the Modbus service is enabled and its listening port is open. This results in a denial-of-service condition. The vulnerability affects version 1.0.0 of the product. No official patch or remediation has been confirmed yet.

Join the discussion
CVE-2026-44100: CWE-306 Missing Authentication for Critical Function in Phoenix Contact CHARX SEC-3150CVE-2026-44100
0

CVE-2026-44100 is a high-severity vulnerability in the Phoenix Contact CHARX SEC-3150 device, specifically in the CHARX JupiCore service. It allows unauthenticated remote attackers to reconfigure charging points, potentially leading to disclosure of charging point unique identifiers (UIDs), denial-of-service conditions, and file tampering. The vulnerability is due to missing authentication for critical functions (CWE-306). Only version 1.0.0 of the product is explicitly affected. No official patch or remediation guidance has been provided yet.

Join the discussion
CVE-2026-44098: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Phoenix Contact CHARX SEC-3150CVE-2026-44098
0

CVE-2026-44098 is an OS command injection vulnerability in Phoenix Contact CHARX SEC-3150 version 1.0.0. It allows an unauthenticated remote attacker who can bypass the firewall and control the OCPP backend to execute arbitrary OS commands as the limited user charx-oa. This could disrupt charging operations. The vulnerability has a high severity with a CVSS score of 8.8. No official patch or remediation guidance is currently available from the vendor.

Join the discussion
CVE-2026-44097: CWE-434 Unrestricted Upload of File with Dangerous Type in Phoenix Contact CHARX SEC-3150CVE-2026-44097
0

CVE-2026-44097 is a vulnerability in Phoenix Contact CHARX SEC-3150 version 1.0.0 that allows a low-privileged remote attacker with operator access to upload arbitrary files via a REST endpoint intended for firmware updates. This can lead to persistent storage of attacker-controlled files and potentially exhaust system resources, causing a denial-of-service condition. The vulnerability has a medium severity rating with a CVSS score of 5.3. No official patch or remediation has been confirmed at this time.

Join the discussion
CVE-2026-44091: CWE-501 Trust Boundary Violation in Phoenix Contact CHARX SEC-3150CVE-2026-44091
0

CVE-2026-44091 is a high-severity vulnerability in Phoenix Contact CHARX SEC-3150 version 1.0.0. An unauthenticated remote attacker can post a malicious ID to the MQTT Broker, causing the system to create a new configuration entry. This behavior can lead to loss of system integrity and availability. No official patch or remediation guidance is currently available from the vendor.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/phoenixcontact/CHARX-SEC-3150
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses