CVE-2026-44092

Summary

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.

Affected Software

VendorProductVersion RangeStatus
Phoenix ContactCHARX SEC-31501.0.0 < 1.9.1affected
Phoenix ContactCHARX SEC-31001.0.0 < 1.9.1affected
Phoenix ContactCHARX SEC-30501.0.0 < 1.9.1affected
Phoenix ContactCHARX SEC-30001.0.0 < 1.9.1affected

Weaknesses

  • CWE-93: CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References