CVE-2026-44107
HIGHDescription
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
Is your site exposed to CVE-2026-44107?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2026-44107? +
How severe is CVE-2026-44107? +
How do I check if I'm vulnerable to CVE-2026-44107? +
Related Vulnerabilities
The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers without …
MISP exposes critical infrastructure settings—specifically the Redis host addresses used by the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs …
Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by …
Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** …
Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated …
Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named …