Impact
The ModbusServer application fails to validate or strip CRLF characters from data received via MQTT, which exposes CWE‑93 (input validation) and CWE‑94 (improper code execution) weaknesses. This missing input validation allows an unauthenticated attacker to inject arbitrary information. The injected payload can corrupt configuration or destabilize the server, causing loss of integrity or availability.
Affected Systems
The vulnerability compromises Phoenix Contact devices model CHARX SEC-3000, CHARX SEC-3050, CHARX SEC-3100, and CHARX SEC-3150. No specific firmware or software version is indicated, so any installed firmware on these models is potentially affected.
Risk and Exploitability
The CVSS score of 8.8 reflects high severity, while the EPSS score of less than 1% suggests exploitation is unlikely in the near term. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is through unauthenticated remote injection over the MQTT channel, where an attacker conveys crafted messages that the server does not sanitize.
OpenCVE Enrichment