CVE-2026-78012
Received Received - Intake

NetStaX EtherNet/IP Stack Buffer Overflow Vulnerability

Vulnerability report for CVE-2026-78012, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: ICS-CERT

Description

An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pyramid_solutions netstax to 5.6.1 (exc)
netstax ethernet_ip_stack to 5.6.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-78012 is a vulnerability in the NetStaX EtherNet/IP Stack prior to version 5.6.1. It involves a silent buffer overflow where large Class 3 explicit-message requests can exceed the application-side receive buffer without generating an error or warning. This may lead to memory corruption, device crashes, or potential remote attacks without the originating device receiving a CIP error indicating the request could not be processed.

Detection Guidance

Monitor network traffic for unusually large Class 3 explicit-message requests targeting EtherNet/IP devices. Check device logs for crashes or memory corruption errors. Use packet inspection tools like Wireshark to filter for EtherNet/IP traffic exceeding expected payload sizes.

Impact Analysis

This vulnerability could allow attackers to exploit buffer overflows to corrupt memory, crash devices, or gain unauthorized remote access. Affected systems may experience unexpected behavior, data loss, or complete device failure. The lack of error warnings means issues may go undetected until severe damage occurs.

Mitigation Strategies

Upgrade NetStaX EtherNet/IP Stack to version 5.6.1 or later to apply compile-time assertions and runtime payload-size checks. Review and update API documentation to clarify buffer relationships and size constants. Implement network-level payload admission limits to match application-layer buffer sizes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78012. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart