CVE-2026-44092

CRITICAL

Missing input validation / stripping of CRLF characters in SystemConfigManager

Title source: cna
STIX 2.1

Description

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.

References (1)

Core 1

Scores

CVSS v3 9.1
EPSS 0.0038
EPSS Percentile 30.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-93
Status published
Products (4)
Phoenix Contact/CHARX SEC-3000 1.0.0 - 1.9.1
Phoenix Contact/CHARX SEC-3050 1.0.0 - 1.9.1
Phoenix Contact/CHARX SEC-3100 1.0.0 - 1.9.1
Phoenix Contact/CHARX SEC-3150 1.0.0 - 1.9.1
Published Jul 30, 2026
Tracked Since Jul 30, 2026