CVE-2026-51536: Buffer Overflow

Published Jul 13, 2026
·
Updated

In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, an upstream length calculated as an int is passed to a downstream function that expects an EipInt16 (a 16-bit signed integer). If a maliciously crafted packet with specific length fields is processed, the length parameter can overflow or be truncated into a negative value. This negative length bypasses subsequent bounds checking (due to signed/unsigned comparison issues) and is ultimately used in memory operations, leading to a Stack Buffer Overflow when reading data in DecodePaddedEPath.

Affected Software

2 affected components
OpENer OpENer=2.3.0
Opener Project Opener=2.3.0

Event History

Jul 13, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can exploit this vulnerability?

An unauthenticated attacker who can send crafted CIP network packets to a vulnerable OpENer instance can trigger the issue. The CVSS vector indicates network reachability, low attack complexity, and no user interaction are required.

2

What is the practical impact of successful exploitation?

Processing a malicious packet can cause a stack buffer overflow in DecodePaddedEPath. The reported CVSS metrics indicate high confidentiality impact and high availability impact, while integrity impact is rated none.

3

How can I determine whether an instance is affected?

The affected version identified in the available data is OpENer 2.3.0 at commit 76b95cf. Review the deployed source version or commit and assess whether the instance accepts incoming CIP network packets.

4

What can be done if updating is not immediately possible?

Restrict network access to the CIP service so untrusted systems cannot send packets to the OpENer instance. Because exploitation requires network packet delivery and no authentication, network segmentation and access controls are the available mitigations supported by the provided data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203