Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-44092— Missing input validation / stripping of CRLF characters in SystemConfigManager

CVSS 9.1 · Critical EPSS 0.38% · P31

Affected Version Matrix 4

VendorProductVersion RangeStatus
Phoenix ContactCHARX SEC-30001.0.0< 1.9.1affected
Phoenix ContactCHARX SEC-30501.0.0< 1.9.1affected
Phoenix ContactCHARX SEC-31001.0.0< 1.9.1affected
Phoenix ContactCHARX SEC-31501.0.0< 1.9.1affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-44092

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Missing input validation / stripping of CRLF characters in SystemConfigManager
Source: CVE Program / CVE List V5
Vulnerability Description
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对CRLF序列的转义处理不恰当(CRLF注入)
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
Phoenix ContactCHARX SEC-3150 1.0.0 ~ 1.9.1 -
Phoenix ContactCHARX SEC-3100 1.0.0 ~ 1.9.1 -
Phoenix ContactCHARX SEC-3050 1.0.0 ~ 1.9.1 -
Phoenix ContactCHARX SEC-3000 1.0.0 ~ 1.9.1 -

II. Public POCs for CVE-2026-44092

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-44092

登录查看更多情报信息。

Vendor Advisories for CVE-2026-44092 (1)

Same Patch Batch · Phoenix Contact · 2026-07-30 · 20 CVEs total

CVE-2026-440909.8 CRITICALMissing authentication for MQTT Broker
CVE-2026-441019.8 CRITICALOCPP reconfiguration vulnerability
CVE-2026-78499.8 CRITICALCommand Injection in SCM (idledisconnect parameter)
CVE-2026-441089.8 CRITICALFirewall bypass during shutdown
CVE-2026-441049.8 CRITICALControllerAgent does not perform validation of firmware
CVE-2026-441009.4 CRITICALJupiCore charging point reconfiguration without auth
CVE-2026-440919.1 CRITICALCreation of a new configuration by posting a malicious ID to MQTT
CVE-2026-440988.6 HIGHOS Command Injection in OCPP Agent via charge_box_id
CVE-2026-440948.6 HIGHFallback to second RAUC slot with default credentials
CVE-2026-440997.8 HIGHLocal Privilege Escalation via pppd password injection
CVE-2026-441067.8 HIGHLocal Privilege Escalation vulnerability in /etc/init.d/user-applications via customer web
CVE-2026-440937.8 HIGHLocal Privilege Escalation vulnerability in /etc/init.d/user-applications via user-applica
CVE-2026-440967.8 HIGHudhcpc Privilege Escalation
CVE-2026-440957.8 HIGHLocal Privilege Escalation via Network scripts
CVE-2026-441077.5 HIGHExposed Reboot via Modbus
CVE-2026-440977.1 HIGHFile Upload vulnerability
CVE-2026-441056.6 MEDIUMCleartext password in logs
CVE-2026-441035.3 MEDIUMJupiCore does not perform validation of firmware
CVE-2026-441025.3 MEDIUMOCPP Firmware download is not properly locked

IV. Related Vulnerabilities

V. Comments for CVE-2026-44092

No comments yet


Leave a comment