CVE-2026-44108
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.51%
- CWE
- CWE-696
- Published
- 2026-07-30
- Last modified
- 2026-07-30
Affected products
- Phoenix Contact CHARX SEC-3150
- Phoenix Contact CHARX SEC-3100
- Phoenix Contact CHARX SEC-3050
- Phoenix Contact CHARX SEC-3000
Weakness type
Related vulnerabilities
- CVE-2026-68930 — Russh: Channel-scoped server callbacks can be reached without an open channel
- CVE-2026-67217 — cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
- CVE-2026-65100 — Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode
- CVE-2026-14169 — ads-tec Industrial IT: Account lockout via non-atomic user creation
- CVE-2026-56355 — GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
- CVE-2026-49318 — Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot
- CVE-2026-49317 — Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot
- CVE-2026-44919 — In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in...