CVE-2026-51541
OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An attacker can send a valid ENIP SendRRData frame carrying a very short CIP payload whose path_size field claims that many more path words are present than are actually available. Because the parser trusts the attacker-controlled path_size and continues decoding path segments without a remaining-length boundary, it reads beyond the end of the stack receive buffer.
Published:Jul 13, 2026
Last Modified:Aug 11, 2026
EPS:Jul 13, 2026
EPSS Score:0.00379
CVSS Score:9.1
Affected Products
Vendor
Product
Action
Vendor
Eipstackgroup
Product
Opener
Eipstackgroup
Opener
Vendor
Opener Project
Product
Opener
Opener Project
Opener
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
