CVE-2026-41032 Details
Description
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
A vulnerability exists in the firmware of Phoenix Contact CHARX SEC-3xxx charging controllers, allowing unauthenticated adjacent attackers to download log files from the controller. This could lead to the disclosure of restricted information. The vulnerability affects CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models, all running firmware prior to 1.9.0.
Users are advised to upgrade to firmware version 1.9.0, which addresses this vulnerability. For general security recommendations regarding network-enabled devices, refer to the Phoenix Contact Application Note Security.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://certvde.com/de/advisories/VDE-2026-060/ | [email protected] | |
| https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-060.json | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | New CVE Received | [email protected] |