CVE-2026-44091

Summary

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.

Affected Software

VendorProductVersion RangeStatus
Phoenix ContactCHARX SEC-31501.0.0 < 1.9.1affected
Phoenix ContactCHARX SEC-31001.0.0 < 1.9.1affected
Phoenix ContactCHARX SEC-30501.0.0 < 1.9.1affected
Phoenix ContactCHARX SEC-30001.0.0 < 1.9.1affected

Weaknesses

  • CWE-501: CWE-501 Trust Boundary Violation

References