CVE-2026-13196
Received Received - Intake

Out-of-bounds Write in KUNBUS piControl

Vulnerability report for CVE-2026-13196, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: Nozomi Networks Inc.

Description

Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker with device configuration access to write attacker-controlled data outside the bounds of the process-image buffer and corrupt adjacent kernel memory, resulting in kernel memory corruption and denial of service, by supplying crafted device configuration data and crafted input through the piControl character device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kunbus pictrol 2.6.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a CWE-787 Out-of-bounds Write vulnerability in KUNBUS piControl version 2.6.2. A local authenticated attacker with device configuration access can exploit it by providing crafted data to write outside the process-image buffer. This corrupts adjacent kernel memory, leading to kernel memory corruption and denial of service.

Detection Guidance

Detection requires identifying the vulnerable KUNBUS piControl version 2.6.2. Check installed versions using system package managers or inspect the piControl character device for abnormal access patterns. Monitor kernel logs for memory corruption errors or denial of service events.

Impact Analysis

An attacker could cause kernel memory corruption and system crashes, resulting in denial of service. Since the attacker needs local authenticated access with device configuration privileges, the impact is limited to systems where such access is already possible.

Compliance Impact

The vulnerability allows local authenticated attackers to corrupt kernel memory and cause denial of service by exploiting an out-of-bounds write in KUNBUS piControl. This could lead to system instability or crashes, potentially disrupting data processing or availability. For compliance standards like GDPR or HIPAA, which require data integrity and availability, such disruptions may violate requirements for secure and reliable system operation.

Mitigation Strategies

Immediately update KUNBUS piControl to the latest patched version. Restrict device configuration access to authorized users only. Disable unnecessary piControl device interfaces if not required. Monitor kernel logs for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13196. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart