(Pwn2Own) Phoenix Contact CHARX SEC-3150 MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability
Vulnerability Details
This vulnerability allows network-adjacent attackers to access internal resources on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the MQTT service. The issue results from the lack of proper validation of a URI prior to accessing resources. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the user-app account.
Additional Details
Fixed in firmware v1.9.1, available by Aug 12, 2026.
https://certvde.com/en/advisories/VDE-2026-008/
Disclosure Timeline
- 2026-02-09 - Vulnerability reported to vendor
- 2026-07-30 - Coordinated public release of advisory
- 2026-07-30 - Advisory Updated
Credit
Giuseppe Calì (_gcali) and 8cf53a459714977f6bb11ee2d90416bf1675fa0e2451d80cf55a06d0b6ac2