Status: UPDATED
| Advisory ID: CVE-2026-44092
Key Details
| CVE | CVE-2026-44092 |
| CVSS Score / Version | 9.1 (Critical) / CVSS v3.1 |
| Updated | 2026-07-30 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high. |
| Affected products | Phoenix Contact CHARX SEC-3150, Phoenix Contact CHARX SEC-3100, Phoenix Contact CHARX SEC-3050, and Phoenix Contact CHARX SEC-3000 |
| Classified as | CWE-93 (Improper Neutralization of CRLF Sequences ('CRLF Injection')) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss. (NVD)
What to Do
Monitor Phoenix Contact's web page for any future patch releases.
References