ZDI-26-512: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-44107.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-512?
The severity of ZDI-26-512 is rated at 6.5 according to the CVSS score.
How do I fix ZDI-26-512?
To fix ZDI-26-512, it is recommended to apply the latest firmware updates from Phoenix Contact for the CHARX SEC-3150 devices.
What type of attack does ZDI-26-512 facilitate?
ZDI-26-512 facilitates a denial-of-service attack on affected installations of the Phoenix Contact CHARX SEC-3150.
Is authentication required to exploit ZDI-26-512?
No, authentication is not required to exploit the ZDI-26-512 vulnerability.
Who is affected by ZDI-26-512?
Organizations using Phoenix Contact CHARX SEC-3150 devices are affected by ZDI-26-512.