Modbus addressing and function codes: why 40001 is register 0
A reference-style guide to Modbus data tables, 0-based versus 1-based addresses, the common function codes and exception responses, with the classic off-by-one trap explained.
· 3 minWhy a perfectly valid register pair turns into nonsense, how IEEE 754 single precision is split across two registers and how to find the right byte and word order.
A 32-bit IEEE 754 single-precision number has one sign bit, an 8-bit exponent and a 23-bit fraction. Written as four bytes from most to least significant, the value 123.456 is 42 F6 E9 79. Call those bytes A, B, C and D.
A Modbus register holds only 16 bits, so the number is split across two registers. Modbus fixes the order of the two bytes inside a register (high byte first on the wire), but it does not say which of the two registers carries the high half of a 32-bit value. Each vendor decides, and that is where the trouble starts.
| Layout | Common name | First register | Second register |
|---|---|---|---|
| ABCD | Big-endian | 0x42F6 | 0xE979 |
| CDAB | Word-swapped (little-endian word order) | 0xE979 | 0x42F6 |
| BADC | Byte-swapped within each word | 0xF642 | 0x79E9 |
| DCBA | Little-endian | 0x79E9 | 0xF642 |
The names are conventions, and different manufacturers use different words for the same layout. Always describe a device by the actual register contents, as in the table, instead of relying on a label.
If the device sends 123.456 as CDAB (E979 42F6) but your software decodes ABCD, the result is not slightly off. It is absurd:
| Device sends | Registers on the wire | Decoded as ABCD |
|---|---|---|
| ABCD | 42F6 E979 | 123.456 |
| CDAB | E979 42F6 | −1.88 × 10²⁵ |
| BADC | F642 79E9 | −9.86 × 10³² |
| DCBA | 79E9 F642 | 1.52 × 10³⁵ |
Values of astronomical magnitude, or values that are plausible only because the true value happens to be small, are a strong hint that the byte or word order is wrong. Be careful with the second case: a wrong order can still produce a believable number for some inputs, so one successful reading is not proof.
Some devices expose a configuration setting for word order. If yours does, change it deliberately and document the setting, because a firmware reset can bring back the default.
Many field devices avoid the problem by exposing a 16-bit integer with a documented scale, for example a temperature of 2345 meaning 23.45 °C. That halves the number of ways to go wrong. When you have the choice, prefer the integer plus scale, and apply the scale once, at the edge, with the factor written in the register map. The industrial data converter applies scaling to register data and exports the result as CSV or JSON.
Start with the basics of Modbus addressing and function codes, then use the register map validation checklist to make byte order, signedness and scaling part of every commissioning.
Let’s look at your machine, your data flow or your production goal together. Describe your situation in a few sentences and the ASP Dijital team will reply by email.