← Back
CVE-2026-44107
high
CVSS 7.5
A reboot of the charging controller can be triggered via Modbus TCP without authentication....
Summary
A reboot of the charging controller can be triggered via Modbus TCP without authentication....
AI summary openai / gpt-4o
この脆弱性は、Modbus TCPを通じて認証なしに充電コントローラを再起動できるというものです。Modbus機能が有効で、CharxModbusServerがリッスンしているポートが開いていると、攻撃者がサービス拒否攻撃を実行できる可能性があります。
❓ What is the problem
Modbus TCPを通じた充電コントローラの再起動
📍 Affected scope
CharxModbusServerがリッスンするポート
🔥 Severity
未認証の攻撃者によるサービス拒否攻撃が可能
🔧 How to fix
Modbus機能の無効化やポートの制限を実施する
🛡️ Workaround
情報なし
🔍 Detection
異常トラフィックを監視し、Modbusポートの不正アクセスを検知する