← Vulnerability feed

Vulnerability record · CVE-2025-25268 · published 8 July 2025

CVE-2025-25268: Phoenixcontact charx sec-3000 firmware missing authentication for critical function vulnerability

Phoenixcontact · Charx Sec 3000 Firmware

An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.

8.8 CVSS 3.1 High EPSS 0.30% · top 79.8% CWE-306 · Missing authentication for critical function
8.8CVSS 3.1 base score
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://certvde.com/de/advisories/VDE-2025-019 Third Party Advisory

Track CVE-2025-25268 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-25270Phoenixcontact charx sec-3000 firmware improper control of dynamically-managed code vulnerabilityAn unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.EPSS 0.65%9.8CVE-2024-6788Phoenixcontact charx sec-3000 firmware vulnerabilityA remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, lo…EPSS 0.50%9.8CVE-2024-26001Phoenixcontact charx sec-3000 firmware out-of-bounds write vulnerabilityAn unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not a…EPSS 0.87%9.8CVE-2024-25995Phoenixcontact charx sec-3000 firmware improper input validation vulnerabilityAn unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper i…EPSS 1.4%9.8CVE-2024-25996Phoenixcontact charx sec-3000 firmware origin validation error vulnerabilityAn unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.EPSS 0.39%8.8CVE-2025-25271Phoenixcontact charx sec-3000 firmware insecure default initialization vulnerabilityAn unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.EPSS 0.29%8.7CVE-2024-26288Phoenixcontact charx sec-3000 firmware cleartext transmission vulnerabilityAn unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affect…EPSS 0.31%8.4CVE-2025-25269Phoenixcontact charx sec-3000 firmware os command injection vulnerabilityAn unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2025-25268), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.