CVE-2026-10703: EIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure use after free
A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRouterRequestStructure of the file cipmessagerouter.c of the component SendRRData Handler. The manipulation leads to use after free. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
EIPStackGroup OpENerfrom your environment.Uninstall or remove OpENer from systems or devices where it is not required to eliminate exposure to the vulnerable component.
- Configuration
If the SendRRData Handler/functionality is not required, disable the SendRRData handler or equivalent feature in OpENer to prevent use of the vulnerable CreateMessageRouterRequestStructure code.
EIPStackGroup OpENer - SendRRData Handler SendRRData Handler = disabled - Compensating control
Restrict network access to devices running OpENer (EtherNet/IP services) using firewall rules, ACLs, or network segmentation so that only trusted hosts/networks can reach the SendRRData/EtherNet/IP service; isolate affected devices from untrusted or public networks.
- Operational
Monitor for exploitation attempts and signs of compromise on systems running OpENer (network and host logs); investigate and contain any suspected incidents. If compromise is suspected, rotate credentials and secrets used by affected systems.
- Operational
Track the OpENer project and vendor advisories for a security update addressing the CreateMessageRouterRequestStructure use-after-free and apply any vendor-supplied fixes or patches as soon as they are released.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10703?
CVE-2026-10703 has a medium severity rating of 6.3.
What type of vulnerability is CVE-2026-10703?
CVE-2026-10703 is categorized as a 'Use After Free' vulnerability.
How does CVE-2026-10703 impact EIPStackGroup OpENer?
CVE-2026-10703 affects the CreateMessageRouterRequestStructure function in the cipmessagerouter.c file, leading to potential remote exploitation.
Which versions of EIPStackGroup OpENer are affected by CVE-2026-10703?
CVE-2026-10703 impacts EIPStackGroup OpENer versions up to 2.3.0.
How do I fix CVE-2026-10703?
To address CVE-2026-10703, upgrade to a patched version of EIPStackGroup OpENer that resolves this vulnerability.