CVE-2026-71255
Received Received - Intake

Out-of-Bounds Write in nanoMODBUS Modbus Client

Vulnerability report for CVE-2026-71255, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c

Description

nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res() function (FC 0x2B/MEI 0x0E, Read Device Identification) in nanomodbus.c. The server-supplied object_length field (0-246) is validated only against the remaining PDU size (res_size_left) and is never validated against the caller-supplied buffers_length parameter. After copying data with strncpy(buffers_out[buf_index], str, buffers_length), the code unconditionally writes a NUL terminator at buffers_out[buf_index][object_length]. When a malicious or compromised Modbus server sends a response with object_length greater than or equal to the client's buffers_length, this NUL write lands past the end of the caller-provided buffer, corrupting adjacent stack or heap memory on the client.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
debevv nanomodbus From 1.0.0 (inc) to 1.23.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

nanoMODBUS through v1.23.0 has an out-of-bounds write flaw in the Modbus client-side function recv_read_device_identification_res() (FC 0x2B/MEI 0x0E). The server-supplied object_length is checked only against remaining PDU size but not the client's buffer length. After copying data with strncpy, it unconditionally writes a NUL terminator at object_length, which can exceed the buffer if object_length is >= buffers_length, corrupting adjacent memory.

Detection Guidance

Detecting this vulnerability requires monitoring for out-of-bounds writes in nanoMODBUS client applications handling Modbus responses. Check for crashes or memory corruption when processing Modbus device identification responses (FC 0x2B/MEI 0x0E). Use tools like AddressSanitizer (ASan) or Valgrind to detect buffer overflows during Modbus communication.

Impact Analysis

This vulnerability can lead to memory corruption on the client side, potentially causing crashes, arbitrary code execution, or data leaks. If exploited by a malicious Modbus server, it may allow attackers to gain control over the affected system or disrupt operations.

Compliance Impact

This vulnerability could lead to data corruption or unauthorized memory access, potentially compromising the integrity and confidentiality of sensitive data processed by systems using nanoMODBUS. This may violate compliance requirements under GDPR (data integrity and confidentiality) and HIPAA (secure handling of protected health information) if exploited in systems handling regulated data.

Mitigation Strategies

Update nanoMODBUS to the latest version beyond v1.23.0 to address the out-of-bounds write issue in the Modbus client-side recv_read_device_identification_res() function. If updating is not possible, restrict network access to Modbus servers or disable the Read Device Identification (FC 0x2B/MEI 0x0E) functionality until a patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71255. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart