Junglewise Threat Intelligence

CVE-2026-48139: NI grpc-device NULL pointer dereference in data moniker service

CVE-2026-48139 · Severity: high · CVSS 7.5 · Published 2026-06-19

Technologies: NI Grpc-Device, NI InstrumentStudio. Vendors: NI.

Executive brief

NI grpc-device is a software component used to interface with test and measurement hardware. A flaw in its data moniker service allows a remote attacker to crash the software by sending a specific malformed value. This results in a denial-of-service condition, potentially interrupting automated testing or industrial monitoring processes.

Technical details

A NULL pointer dereference (CWE-476) exists in the data moniker service of NI grpc-device versions 2.17.0 and prior. The vulnerability is triggered when the service receives an unexpected or 'unknown' value, leading to an application crash. The attack can be executed over the network without authentication or user interaction. Successful exploitation results in a complete loss of availability for the device interface service. The issue is resolved in NI grpc-device version 2.18.0.

Affected products

  • NI grpc-device <= 2.17.0
  • NI InstrumentStudio <= 26.3.0

Timeline

  • 2026-06-19: disclosed
  • 2026-06-19: advisory
  • 2026-06-19: patched: Fixed in version 2.18.0

References

Related threats