CRLF injection in Phoenix Contact GmbH products - CVE-2026-44092
Published: July 31, 2026
CHARX SEC-3000
CHARX SEC-3050
CHARX SEC-3100
CHARX SEC-3150
Detailed vulnerability description
The vulnerability allows a remote attacker to inject arbitrary data in server response.
The vulnerability exists due to insufficient validation of attacker-supplied data within the charx-system-config-manager service. A remote attacker can pass specially crafted data to the application containing CR-LF characters and modify application behavior.