CVE-2026-44107
Severity CVSS v4.0:
HIGH
Type:
CWE-749
Exposed Dangerous Method or Function
Publication date:
30/07/2026
Last modified:
30/07/2026
Description
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH



