CVE-2026-10703: EIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure use after free

Published Jun 3, 2026
·
Updated

A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRouterRequestStructure of the file cipmessagerouter.c of the component SendRRData Handler. The manipulation leads to use after free. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

1 affected component
EIPStackGroup OpENer<=2.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove EIPStackGroup OpENer from your environment.

    Uninstall or remove OpENer from systems or devices where it is not required to eliminate exposure to the vulnerable component.

  2. Configuration

    If the SendRRData Handler/functionality is not required, disable the SendRRData handler or equivalent feature in OpENer to prevent use of the vulnerable CreateMessageRouterRequestStructure code.

    EIPStackGroup OpENer - SendRRData Handler SendRRData Handler = disabled
  3. Compensating control

    Restrict network access to devices running OpENer (EtherNet/IP services) using firewall rules, ACLs, or network segmentation so that only trusted hosts/networks can reach the SendRRData/EtherNet/IP service; isolate affected devices from untrusted or public networks.

  4. Operational

    Monitor for exploitation attempts and signs of compromise on systems running OpENer (network and host logs); investigate and contain any suspected incidents. If compromise is suspected, rotate credentials and secrets used by affected systems.

  5. Operational

    Track the OpENer project and vendor advisories for a security update addressing the CreateMessageRouterRequestStructure use-after-free and apply any vendor-supplied fixes or patches as soon as they are released.

Event History

Jun 3, 2026
CVE Published
via MITRE·12:30 AM
Data Sourced
via MITRE·12:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-10703?

CVE-2026-10703 has a medium severity rating of 6.3.

2

What type of vulnerability is CVE-2026-10703?

CVE-2026-10703 is categorized as a 'Use After Free' vulnerability.

3

How does CVE-2026-10703 impact EIPStackGroup OpENer?

CVE-2026-10703 affects the CreateMessageRouterRequestStructure function in the cipmessagerouter.c file, leading to potential remote exploitation.

4

Which versions of EIPStackGroup OpENer are affected by CVE-2026-10703?

CVE-2026-10703 impacts EIPStackGroup OpENer versions up to 2.3.0.

5

How do I fix CVE-2026-10703?

To address CVE-2026-10703, upgrade to a patched version of EIPStackGroup OpENer that resolves this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203