CVE-2026-44107

Summary

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.

Affected Software

VendorProductVersion RangeStatus
Phoenix ContactCHARX SEC-31501.0.0 < 1.9.1affected
Phoenix ContactCHARX SEC-31001.0.0 < 1.9.1affected
Phoenix ContactCHARX SEC-30501.0.0 < 1.9.1affected
Phoenix ContactCHARX SEC-30001.0.0 < 1.9.1affected

Weaknesses

  • CWE-749: CWE-749 Exposed Dangerous Method or Function

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References