What is CVE-2026-44107?
The CVE-2026-44107 vulnerability allows an unauthenticated attacker to trigger a reboot of the charging controller via Modbus TCP. When the Modbus functionality is enabled and the port for CharxModbusServer is open, a remote Denial-of-Service (DoS) attack can be performed. It is recommended to restrict network access to the Modbus port.
Azərbaycanca: CVE-2026-44107 zəifliyi, autentifikasiya olmadan Modbus TCP üzərindən doldurma nəzarətçisinin (charging controller) yenidən başladılmasına imkan verir. CharxModbusServer-in dinlədiyi port açıq olduqda, uzaqdan bir hücumçu xidmət əleyhinə (Denial-of-Service) hücum həyata keçirə bilər. Modbus funksionallığı aktivdirsə, portun xarici şəbəkəyə bağlanması tövsiyə olunur.
FAQ2
Is authentication required to exploit CVE-2026-44107?
No, this vulnerability does not require any authentication. An unauthenticated attacker can trigger a reboot of the charging controller via Modbus TCP.
What mitigation is recommended for CVE-2026-44107?
If Modbus functionality is enabled, it is recommended to restrict network access to the Modbus port.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.