What is CVE-2026-71255?
CVE-2026-71255 identifies an out-of-bounds write vulnerability in the Modbus client-side `recv_read_device_identification_res()` function of nanoMODBUS up to v1.23.0. Improper validation of the server-supplied `object_length` field allows a malicious server to overwrite memory, potentially enabling remote code execution. Users should update to the latest patched version immediately.
Azərbaycanca: CVE-2026-71255 nanoMODBUS-un v1.23.0-a qədər versiyalarında Modbus müştəri tərəfində `recv_read_device_identification_res()` funksiyasında "out-of-bounds write" zəifliyini aşkar edir. Serverdən gələn `object_length` sahəsi düzgün yoxlanılmadığı üçün hücumçu xüsusi hazırlanmış cavabla yaddaşda yazma sərhədini aşa, potensial olaraq uzaqdan kod icrasına səbəb ola bilər. nanoMODBUS istifadəçiləri dərhal ən son versiyaya yeniləməli və ya təsirlənmiş funksiyaya edilən çağırışları məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
Which versions of nanoMODBUS are affected by CVE-2026-71255?
CVE-2026-71255 affects nanoMODBUS versions up to v1.23.0.
What outcome can an attacker achieve by exploiting CVE-2026-71255?
A malicious server can overwrite memory via a crafted response, potentially enabling remote code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.