CVE-2026-78012: Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack
An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pyramid Solutions NetStaX EtherNet/IP Stackto a version that resolves this vulnerability.Fixed in v5.6.1
Event History
Frequently Asked Questions
Which deployments should be prioritized for remediation?
Devices using Pyramid Solutions NetStaX EtherNet/IP Stack versions earlier than 5.6.1 should be prioritized, particularly where they accept Class 3 explicit-message requests over the network.
What does an attacker need to exploit this issue?
An attacker needs to send a large Class 3 explicit-message request to an affected stack. The supplied severity vector indicates network reachability, low attack complexity, and no required privileges or user interaction.
Can the originating device reliably detect that an oversized request was rejected?
No. The affected stack can exceed the application-side receive buffer without producing an error or warning, and the originating device does not receive a CIP error indicating that the request could not be processed.