CVE-2025-24002

An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restarted by the watchdog.
References
Link Resource
https://certvde.com/en/advisories/VDE-2025-014 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:phoenixcontact:charx_sec-3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:phoenixcontact:charx_sec-3050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3050:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:phoenixcontact:charx_sec-3100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3100:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:phoenixcontact:charx_sec-3150_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3150:-:*:*:*:*:*:*:*

History

11 Jul 2025, 14:36

Type Values Removed Values Added
References () https://certvde.com/en/advisories/VDE-2025-014 - () https://certvde.com/en/advisories/VDE-2025-014 - Third Party Advisory
CPE cpe:2.3:o:phoenixcontact:charx_sec-3100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3100:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:charx_sec-3150_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3000:-:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3050:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:charx_sec-3050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:phoenixcontact:charx_sec-3150:-:*:*:*:*:*:*:*
cpe:2.3:o:phoenixcontact:charx_sec-3000_firmware:*:*:*:*:*:*:*:*
First Time Phoenixcontact charx Sec-3100 Firmware
Phoenixcontact charx Sec-3000
Phoenixcontact
Phoenixcontact charx Sec-3150
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3000 Firmware
Phoenixcontact charx Sec-3050 Firmware
Phoenixcontact charx Sec-3150 Firmware
Phoenixcontact charx Sec-3050

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) Un atacante remoto no autenticado puede usar mensajes MQTT para bloquear un servicio en estaciones de carga que cumplen con la Ley de Calibración Alemana, lo que genera una denegación de servicio temporal para estas estaciones hasta que sean reiniciadas por el organismo de control.

08 Jul 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-08 07:15

Updated : 2025-07-11 14:36


NVD link : CVE-2025-24002

Mitre link : CVE-2025-24002

CVE.ORG link : CVE-2025-24002


JSON object : View

Products Affected

phoenixcontact

  • charx_sec-3100
  • charx_sec-3000_firmware
  • charx_sec-3150
  • charx_sec-3050_firmware
  • charx_sec-3050
  • charx_sec-3000
  • charx_sec-3150_firmware
  • charx_sec-3100_firmware
CWE
CWE-20

Improper Input Validation