
Working exploit for Phoenix Contact CHARX SEC-3100 using Scapy raw Ethernet packets to trigger vulnerabilities and obtain an interactive connect-back shell.
This exploit was submitted successfully against the Phoenix Contact CHARX SEC-3100 during Pwn2Own Automotive 2024.
An accompanying blog post covers some of our research process and details on the vulnerabilities found, with a follow-up post on the actual exploitation techniques used.
Running the exploit requires:
Once the exploit succeeds, there will be an interactive connect-back shell running as the charx-ca user (for the ControllerAgent service).