What is CVE-2026-10848?
CVE-2026-10848 is a critical vulnerability found in the OCPP 1.6 client library (subsys/net/lib/ocpp/ocpp_j.c) of Zephyr RTOS, specifically in the parse_rpc_msg() function. The issue stems from a hand-rolled extract_string_field() function improperly parsing inbound WAMP RPC frames. Users with affected Zephyr-based devices should apply the upcoming patch from the Zephyr project.
Azərbaycanca: CVE-2026-10848 Zephyr RTOS-un OCPP 1.6 müştəri kitabxanasında (subsys/net/lib/ocpp/ocpp_j.c) parse_rpc_msg() funksiyasında aşkarlanmış kritik zəiflikdir. Bu, əl ilə yazılmış extract_string_field() funksiyasının WAMP RPC çərçivələrini düzgün şəkildə parse etməməsi səbəbindən baş verir. Təsirə məruz qalan cihazları olan istifadəçilər Zephyr layihəsinin buraxacağı yeniləməni tətbiq etməlidir.
FAQ2
In which component of Zephyr RTOS was CVE-2026-10848 discovered?
CVE-2026-10848 was discovered in the OCPP 1.6 client library of Zephyr RTOS, specifically in the parse_rpc_msg() function within the subsys/net/lib/ocpp/ocpp_j.c file.
What is the root cause of CVE-2026-10848?
The root cause of the vulnerability is the hand-rolled extract_string_field() function improperly parsing inbound WAMP RPC frames.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.