Description
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
Published: 2026-07-30
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote reboot can be triggered by sending a Modbus TCP command to the charging controller without any authentication. The reboot resets the unit, temporarily making it unavailable and thereby causing a denial‑of‑service condition. The weakness arises from improper access control – an attacker can issue the reboot command to anyone who can reach the Modbus TCP port used by the CharxModbusServer.

Affected Systems

The vulnerability affects Phoenix Contact’s CHARX SEC‑3000, CHARX SEC‑3050, CHARX SEC‑3100, and CHARX SEC‑3150 charging controller models. No specific firmware or software version numbers are supplied in the advisory; operators should verify whether their installed units are impacted.

Risk and Exploitability

With a CVSS score of 8.7 the flaw is considered high severity, yet the EPSS score is reported below 1%, indicating a very low exploitation probability at present. The attack requires only network reachability to the Modbus TCP port, no authentication, and can be performed by any unauthenticated actor with access to the port. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 3, 2026 at 11:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • If Modbus functionality is unnecessary, turn off the CharxModbusServer or block the Modbus TCP port with a firewall rule.
  • Check Phoenix Contact’s website for a firmware or software update that resolves the reboot issue and deploy the patch as soon as it becomes available.
  • Implement network segmentation or access control lists so that only trusted devices can reach the Modbus port, and monitor traffic for unauthorized reboot attempts.

Generated by OpenCVE AI on August 3, 2026 at 11:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150
Vendors & Products Phoenixcontact
Phoenixcontact charx Sec-3000
Phoenixcontact charx Sec-3050
Phoenixcontact charx Sec-3100
Phoenixcontact charx Sec-3150

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
Title Exposed Reboot via Modbus
First Time appeared Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
Weaknesses CWE-749
CPEs cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*
Vendors & Products Phoenix Contact
Phoenix Contact charx Sec 3000
Phoenix Contact charx Sec 3050
Phoenix Contact charx Sec 3100
Phoenix Contact charx Sec 3150
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Phoenix Contact Charx Sec 3000 Charx Sec 3050 Charx Sec 3100 Charx Sec 3150
Phoenixcontact Charx Sec-3000 Charx Sec-3050 Charx Sec-3100 Charx Sec-3150
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-30T15:16:52.455Z

Reserved: 2026-05-05T10:48:08.227Z

Link: CVE-2026-44107

cve-icon Vulnrichment

Updated: 2026-07-30T15:13:25.733Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T07:16:59.157

Modified: 2026-07-30T16:17:12.010

Link: CVE-2026-44107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:03Z

Weaknesses
  • CWE-749

    Exposed Dangerous Method or Function