CVE-2026-75348
Deferred Deferred - Pending Action

Out-of-Bounds Read in EIPStackGroup OpENer

Vulnerability report for CVE-2026-75348, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: MITRE

Description

An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TCP SendRRData Common Packet Format parser. The issue occurs in CreateCommonPacketFormatStructure() when it parses recognized optional socket address information items of type 0x8000 or 0x8001 without first validating that the remaining CPF buffer contains the complete fixed sockaddr structure. This allows a remote attacker to cause a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-75348 is an out-of-bounds read vulnerability in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf. It occurs in the EtherNet/IP TCP SendRRData Common Packet Format parser when parsing optional socket address information items of type 0x8000 or 0x8001. The function CreateCommonPacketFormatStructure() fails to validate that the remaining CPF buffer contains the complete fixed sockaddr structure before reading it, allowing a remote attacker to cause a denial of service.

Detection Guidance

Monitor network traffic on port 44818 for malformed EtherNet/IP packets. Use tools like Wireshark with custom dissectors to analyze TCP streams for truncated sockaddr items (0x8000 or 0x8001). Enable AddressSanitizer (ASan) in OpENer builds to detect stack-buffer-overflows during parsing.

Impact Analysis

This vulnerability can be exploited remotely by an attacker establishing a TCP session on port 44818. They can send a RegisterSession packet followed by a malformed SendRRData packet to crash the system. In ASan builds, this causes a stable stack-buffer-overflow read. In non-ASan builds, it results in a remotely reachable denial of service and potential misinterpretation of memory beyond intended boundaries.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service attacks that disrupt critical systems handling sensitive data. GDPR requires protecting personal data integrity, while HIPAA mandates availability of healthcare systems. A remotely triggered crash could violate these requirements by compromising system availability.

Mitigation Strategies

Update OpENer to the latest patched version. Implement input validation to check buffer lengths before parsing sockaddr structures. Block or filter malformed packets at the network perimeter using firewalls or IDS rules targeting port 44818.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75348. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart