(Pwn2Own) Phoenix Contact CHARX SEC-3150 MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability

July 30th, 2026

Vulnerability Details

This vulnerability allows network-adjacent attackers to access internal resources on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the MQTT service. The issue results from the lack of proper validation of a URI prior to accessing resources. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the user-app account.

Additional Details

Fixed in firmware v1.9.1, available by Aug 12, 2026.
https://certvde.com/en/advisories/VDE-2026-008/


Disclosure Timeline

  • 2026-02-09 - Vulnerability reported to vendor
  • 2026-07-30 - Coordinated public release of advisory
  • 2026-07-30 - Advisory Updated

Credit

Giuseppe Calì (_gcali) and 8cf53a459714977f6bb11ee2d90416bf1675fa0e2451d80cf55a06d0b6ac2

Back to Advisories