PT-2026-66420 · Phoenix Contact · Charx Sec-3000+3

CVE-2026-44092

·

Published

2026-07-30

·

Updated

2026-07-30

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44092

Affected Products

Charx Sec-3000
Charx Sec-3050
Charx Sec-3100
Charx Sec-3150