CVE-2026-18368: Heap buffer overflow in Modbusgwd
In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request data. A remote, unauthenticated attacker with access to the affected service could trigger a heap-based buffer overflow, resulting in a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Teltonika Networks RUTOS (modbusgwd)to a version that resolves this vulnerability.Fixed in 7.24.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18368?
CVE-2026-18368 has a risk score of 54, indicating a moderate severity level.
What type of vulnerability is CVE-2026-18368?
CVE-2026-18368 is classified as a heap buffer overflow vulnerability.
How can CVE-2026-18368 be exploited?
CVE-2026-18368 can be exploited by a remote, unauthenticated attacker who can send crafted Modbus TCP requests to trigger a buffer overflow.
What are the potential consequences of CVE-2026-18368?
The potential consequences of CVE-2026-18368 include a denial of service, causing the affected devices to crash or become unresponsive.
How do I fix CVE-2026-18368?
To fix CVE-2026-18368, it is recommended to apply the relevant security patches provided by Teltonika Networks as soon as they are available.