PT-2026-66435 · Phoenix Contact · Charx Sec-3000+3

CVE-2026-44107

·

Published

2026-07-30

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44107

Affected Products

Charx Sec-3000
Charx Sec-3050
Charx Sec-3100
Charx Sec-3150