# CVE-2026-44107

## Summary

- **CVE ID:** CVE-2026-44107
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-749
- **Published:** Jul 30, 2026
- **Last Modified:** Jul 30, 2026

## Description

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.

## Affected Products

- Phoenix Contact — CHARX SEC-3150 (1.0.0)
- Phoenix Contact — CHARX SEC-3100 (1.0.0)
- Phoenix Contact — CHARX SEC-3050 (1.0.0)
- Phoenix Contact — CHARX SEC-3000 (1.0.0)

## References

- [CNA](https://www.certvde.com/en/advisories/VDE-2026-008/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.31%
- **EPSS Percentile:** 23.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._