CVE-2026-75349
Deferred Deferred - Pending Action

Out-of-Bounds Read in EIPStackGroup OpENer

Vulnerability report for CVE-2026-75349, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: MITRE

Description

EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability in Connection Manager request parsing. This allows a remote attacker to cause a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-75349 is a remote stack-buffer-overflow vulnerability in the OpENer EtherNet/IP stack affecting the Connection Manager services. A crafted EtherNet/IP SendRRData request with a long padded EPath can consume the entire CIP payload, leaving zero request body data. This causes the server to read past the end of the stack receive buffer when handling three specific services: ForwardClose, GetConnectionData, and SearchConnectionData.

Detection Guidance

Monitor for crashes in OpENer's Connection Manager services (ForwardClose, GetConnectionData, SearchConnectionData) when processing EtherNet/IP SendRRData requests. Use network traffic analysis tools like Wireshark to inspect for malformed EtherNet/IP packets with long padded EPaths. Enable AddressSanitizer or similar tools during compilation to detect out-of-bounds reads in the stack buffer.

Impact Analysis

This vulnerability can be exploited without authentication, leading to a denial of service via server crash. It is network-reachable through the TCP explicit messaging path, meaning an attacker could remotely crash the affected system by sending a specially crafted request.

Compliance Impact

This vulnerability, a remote stack-buffer-overflow in the OpENer EtherNet/IP stack, could lead to denial of service via server crashes. For industrial systems handling sensitive data, such disruptions may violate compliance requirements under GDPR (data availability) or HIPAA (operational integrity) if critical infrastructure is impacted.

Mitigation Strategies

Apply the official patch from OpENer's repository that adds request_data_size validation checks in the affected handlers. If a patch is unavailable, restrict network access to the EtherNet/IP TCP explicit messaging port (typically 44818) using firewalls. Monitor for exploitation attempts and update to the latest stable version of OpENer once a fix is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75349. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart