(Pwn2Own) Phoenix Contact CHARX SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability

July 30th, 2026

Vulnerability Details

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the generation of log files. The issue results from including sensitive information in a log file. An attacker can leverage this vulnerability to bypass authentication on the system.

Additional Details

Fixed in firmware v1.9.1, available by Aug 12, 2026.
https://certvde.com/en/advisories/VDE-2026-008/


Disclosure Timeline

  • 2026-02-09 - Vulnerability reported to vendor
  • 2026-07-30 - Coordinated public release of advisory
  • 2026-07-30 - Advisory Updated

Credit

Nabih Benazzouz from Fuzzinglabs, Julien Cohen-Scali from Fuzzinglabs, Hugo Leclercq from Fuzzinglabs, Patrick Ventuzelo from Fuzzinglabs

Back to Advisories