CVE-2026-44098
Phoenix Contact CHARX SEC-3150, CHARX SEC-3100, CHARX SEC-3050
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.
- CVSS
- 8.8
- EPSS
- 1.37% 69.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.30