ZDI-26-516: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-44090.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-516?
ZDI-26-516 has been assigned a CVSS rating of 6.5, indicating a medium severity level.
How do I fix ZDI-26-516?
To mitigate ZDI-26-516, ensure that the Phoenix Contact CHARX SEC-3150 device is updated to the latest firmware version provided by the vendor.
What type of attack does ZDI-26-516 enable?
ZDI-26-516 enables network-adjacent attackers to perform a denial-of-service attack on affected Phoenix Contact CHARX SEC-3150 devices.
Is authentication required to exploit ZDI-26-516?
No, authentication is not required to exploit ZDI-26-516, making it easier for attackers to launch an attack.
What devices are affected by ZDI-26-516?
The vulnerability ZDI-26-516 specifically affects the Phoenix Contact CHARX SEC-3150 devices.