(Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability

July 30th, 2026

Vulnerability Details

This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the charx-system-config-manager service. The issue results from incorrect neutralization of CRLF sequences. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the user-app user.

Additional Details

Fixed in firmware v1.9.1, available by Aug 12, 2026.
https://certvde.com/en/advisories/VDE-2026-008/


Disclosure Timeline

  • 2026-02-09 - Vulnerability reported to vendor
  • 2026-07-30 - Coordinated public release of advisory
  • 2026-07-30 - Advisory Updated

Credit

Giuseppe Calì (_gcali) and 8cf53a459714977f6bb11ee2d90416bf1675fa0e2451d80cf55a06d0b6ac2

Back to Advisories