VYPR
advisoryPublished Jul 30, 2026· 1 source

Phoenix Contact CHARX SEC-3150 ModBus Server Vulnerable to Denial-of-Service

A denial-of-service vulnerability (CVE-2026-44090) has been discovered in the ModBus server of Phoenix Contact CHARX SEC-3150 devices, allowing network-adjacent attackers to disrupt operations.

A critical denial-of-service (DoS) vulnerability has been identified in the ModBus server component of Phoenix Contact's CHARX SEC-3150 industrial devices. Tracked as CVE-2026-44090, the flaw allows network-adjacent attackers to disrupt the normal operation of affected systems without requiring any form of authentication.

The vulnerability resides within the CharxModbusServer, which typically listens on port 502. The root cause is an exposed dangerous function that, when triggered by a specially crafted request, can lead to a denial-of-service condition. This means an attacker could render the device unresponsive, potentially leading to significant operational downtime in industrial environments.

Exploitation of this vulnerability does not require prior access or credentials, making it a significant threat for devices exposed to network segments that attackers can reach. The CVSS rating for this vulnerability is 6.5, indicating a moderate-to-high severity risk, primarily due to the ease of exploitation and the potential impact on critical infrastructure.

Phoenix Contact has addressed this vulnerability by releasing firmware version v1.9.1. Users are strongly advised to update their devices to this latest firmware as soon as possible to mitigate the risk. The updated firmware was made available by August 12, 2026. Further details and advisories can be found via CERT VDE at https://certvde.com/en/advisories/VDE-2026-008/.

The vulnerability was initially reported to the vendor on February 9, 2026. Following a coordinated disclosure process, the advisory was publicly released on July 30, 2026, with an update to the advisory also published on the same date. This timeline indicates a standard vendor response and disclosure period.

The discovery and reporting of this vulnerability are credited to Giuseppe Calì, also known by their handle '_gcali', and a collaborator identified by a SHA-256 hash. Their work highlights the ongoing efforts by security researchers to uncover vulnerabilities in industrial control systems and operational technology (OT) devices.

This DoS vulnerability adds to a growing list of security concerns for industrial control systems, emphasizing the need for robust security practices, regular patching, and network segmentation to protect critical infrastructure from potential disruptions. The CHARX SEC-3150 is used in various industrial applications, making its security paramount.

Synthesized by Vypr AI