Quick answer: A Modbus Float32 value occupies two consecutive 16-bit registers. Read both registers (quantity 2), interpret them as IEEE-754 Float32, then select the byte order the device uses: ABCD (big-endian), CDAB (word swap), BADC (byte swap) or DCBA (little-endian). If the number looks absurd, the byte order is usually wrong.

A Modbus register is only 16 bits. To carry a 32-bit value - a Float32 (IEEE 754) temperature, a UInt32 counter, an Int32 measurement - a device uses two consecutive registers. The catch is that vendors do not agree on the order of those bytes, which is why a reading that should say 123.45 sometimes shows up as a huge nonsense number.

What do ABCD, DCBA, BADC and CDAB mean?

Call the four bytes of the 32-bit value A B C D (A is the most significant byte). They are packed into two registers, but the order can be swapped at the word level and at the byte level. The four common combinations are:

OrderRegister 1Register 2Also called
ABCDA BC DBig-endian
DCBAD CB ALittle-endian
BADCB AD CBig-endian, byte swap
CDABC DA BWord swap (common on Siemens)

How do you read a Float32 value over Modbus?

  1. Read 2 consecutive registers starting at the value's address (for example a holding register read of quantity 2).
  2. Set the display format to Float32 (or Int32 / UInt32 for integers).
  3. If the number looks wrong, change the byte order until it reads correctly - try CDAB and DCBA first, they are the most common culprits.

What does a word-swapped Float32 look like?

Suppose the value 123.45 (hex 0x42F6E666) is stored as bytes A=42, B=F6, C=E6, D=66. A device using ABCD sends register 1 = 0x42F6 and register 2 = 0xE666. A device using CDAB sends register 1 = 0xE666 and register 2 = 0x42F6. Same value, swapped words - if your tool assumes the wrong order, the float is garbage.

How do Float64, Int64 and UInt64 byte orders work?

A 64-bit value (Float64 / IEEE 754 double, Int64 or UInt64) spans four consecutive registers. Call its eight bytes A B C D E F G H (A most significant). The same four order names are used, extended to four words:

64-bit byte order: bytes A-H of the value (A = most significant) as they appear on the wire, register 1 first. Example: Float64 123.456 = 0x405EDD2F1A9FBE77.
Order8-byte sequence on the wireReg 1Reg 2Reg 3Reg 4Float64 123.456 registersMeaning
ABCDA B C D E F G HA BC DE FG H405E DD2F 1A9F BE77Big-endian
DCBAH G F E D C B AH GF ED CB A77BE 9F1A 2FDD 5E40Little-endian (word order reversed and bytes swapped)
BADCB A D C F E H GB AD CF EH G5E40 2FDD 9F1A 77BEByte-swapped within each word
CDABG H E F C D A BG HE FC DA BBE77 1A9F DD2F 405EWord-swapped (all four words reversed)

Note that for 64-bit values CDAB reverses all four words (GH EF CD AB), not just the two halves. This is how ModbusBB 2.0 decodes and writes Float64, Int64 and UInt64 in each order.

Read a quantity of 4 (or a multiple of 4) starting at the first register of the value. Energy meters often use 64-bit counters for total energy, so an energy value that jumps or looks absurd is often a byte-order or start-address problem.

How are strings stored in Modbus registers?

Text such as a serial number, model name or firmware version is usually packed as two ASCII characters per register. Normally the high byte holds the first character. Some devices put the low byte first, which turns "ABCD" into "BADC". For strings, only this byte swap matters: ModbusBB treats byte order BADC or DCBA as "low byte first" and ABCD or CDAB as "high byte first". Trailing zero bytes are padding.

Which data types and byte orders does ModbusBB 2.0 support?

ModbusBB 2.0 decodes and writes UInt16, Int16, Hex, Binary, Float32, Int32, UInt32, Float64, Int64, UInt64 and String, each with ABCD, DCBA, BADC or CDAB order. In the GUI, every row of the register grid has its own Format and Byte Order columns. Cycle Byte Order (button or right-click menu) steps through the four orders until the value makes sense. A register map can also set a scale, an offset and a unit to produce an engineering value.

Per-row format and byte order in ModbusBB 2.0, including 64-bit and string types.

From the command line, use --format and --byte-order (and --string-length in characters for strings):

ModbusBB.CLI read --tcp 192.168.1.10 --input --address 0 --format float64 --byte-order CDAB
ModbusBB.CLI read --tcp 192.168.1.10 --address 100 --format string --string-length 16

See the data types documentation and the read command.

Don't forget scaling

Some devices store a value as a scaled 16-bit integer instead of a float - for example raw 1234 meaning 123.4 °C (scale 0.1). If a "float" still looks off after trying every byte order, check the device manual for a scale factor.

Try it with ModbusBB

ModbusBB lets you switch a register's format (16-bit, 32-bit, 64-bit or String) and cycle the byte order (ABCD/DCBA/BADC/CDAB) per row, so you can find the right interpretation in seconds. Its simulator can also serve 32-bit and 64-bit values in any byte order for testing, including from value generators. Download the free trial.

Frequently asked questions

Why does my Modbus float value show a huge or nonsense number?

The two registers are being combined in the wrong order. Try the other byte orders (CDAB and DCBA are the most common fixes) and confirm you started reading at the first register of the pair. If no order gives a sensible value, the device may store a scaled integer instead of a float.

What is CDAB byte order in Modbus?

CDAB, often called word swap, sends the low 16-bit word first and the high word second while keeping the byte order inside each word. For 123.45 (0x42F6E666), a CDAB device sends 0xE666 and then 0x42F6.

How many registers does a Modbus Float32 use?

Two. Every Modbus register is 16 bits, so any 32-bit value (Float32, Int32 or UInt32) spans two consecutive registers and should be read with a quantity of 2 or more.

How many registers does a Float64 or Int64 value use?

Four. A 64-bit value (Float64, Int64 or UInt64) spans four consecutive 16-bit registers. Read a quantity of 4 from the first register and try the ABCD, CDAB, BADC and DCBA orders if the value looks wrong.

Keep Learning

Next: what Modbus exception codes mean and how to fix them.