CVE-2026-82358: RT-Labs AB C-Open CANopen SDO Server Write Protection Bypass

Published Oct 1, 2026
·
Updated

RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/cosdoserver.c' that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1.

Affected Software

1 affected component
RT-Labs AB C-Open CANopen<1.1.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade RT-Labs AB C-Open CANopen to a version that resolves this vulnerability.

    Fixed in 1.1.1

Event History

Oct 1, 2026
CVE Published
via MITRE·07:42 PM
Data Sourced
via MITRE·07:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated attacker who can send CANopen traffic on the CAN bus can exploit it. CANopen does not provide built-in authentication mechanisms.

2

What does an attacker need to send?

The attacker can initiate an SDO upload for a read-only Object Dictionary entry and then send download-segment frames targeting the resulting data pointer. The issue can be triggered using two SDO frames.

3

Which release fixes the issue?

RT-Labs AB C-Open CANopen version 1.1.1 includes the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203