CVE-2026-44107 HIGH

CVE-2026-44107: Exposed Reboot via Modbus

Vendor Phoenix Contact
Product CHARX SEC-3150
Weakness CWE-749
Published July 30, 2026
Last update July 30, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.

Key dates

02Disclosure timeline

July 30, 2026 CVE published
July 30, 2026 Record updated