Back to Database
Status published
High
CVE-2024-25998
PHOENIX CONTACT: Command injection in the OCPP Service
Vulnerability Description
An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-25998
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Chris Anastasio
- Fabius Watson
More from PHOENIX CONTACT
View All →CVE-2025-41668
Phoenix Contact: File access due to the replacement of a critical file used by the service security-profile
High
8.8
CVE-2025-41667
Phoenix Contact: File access due to the replacement of a critical file used by the arp-preinit script
High
8.8
CVE-2025-41666
Phoenix Contact: File access due to the replacement of a critical file used by the watchdog
High
8.8
CVE-2025-41665
Phoenix Contact: DoS of the PLC due to incorrect default permissions possible
Medium
6.5
CVE-2024-7734
Phoenix Contact: Multiple mGuard devices are vulnerable to a drain of open file descriptors.
Medium
5.3
Affected Vendor
PHOENIX CONTACT
View all reports →Affected Software
CHARX SEC-3000, CHARX SEC-3050, CHARX SEC-3100, CHARX SEC-3150
Vulnerable Versions:
0
Timeline
Official Publish:
March 12th, 2024
Last Modified:
January 24th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L