Status: UPDATED
| Advisory ID: CVE-2026-44107
Key Details
| CVE | CVE-2026-44107 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-07-30 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high. |
| Affected products | Phoenix Contact CHARX SEC-3150, Phoenix Contact CHARX SEC-3100, Phoenix Contact CHARX SEC-3050, and Phoenix Contact CHARX SEC-3000 |
| Classified as | CWE-749 (Exposed Dangerous Method or Function) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack. (NVD)
What to Do
Monitor Phoenix Contact's web page for any future patch releases.
References