SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-44107

HIGH · CVSS 7.5 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated attackers to trigger a reboot of the charging controller through Modbus TCP, leading to a Denial-of-Service condition. This poses a significant risk to systems utilizing the CharxModbusServer, particularly in environments where Modbus functionality is enabled and exposed. Organizations managing charging infrastructure should prioritize addressing this issue to prevent potential service disruptions.

CVE
CVE-2026-44107
Severity
HIGH
CVSS
7.5
EPSS
0.31%

Original NVD Description

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.