Junglewise Threat Intelligence

CVE-2026-51540: EIPStackGroup OpENer integer underflow in SendUnitData processing

CVE-2026-51540 · Severity: info · CVSS 7.5 · Published 2026-07-13

Technologies: EIPStackGroup OpENer. Vendors: EIPStackGroup.

Executive brief

OpENer is an open-source implementation of the EtherNet/IP protocol used in industrial automation and control systems. A security flaw allows a remote attacker to send a specially crafted message that causes the software to crash. This results in a denial-of-service condition, potentially disrupting industrial processes and communication between networked devices.

Technical details

An integer underflow vulnerability exists in OpENer 2.3.0 (up to commit 76b95cf) within the handling of connected explicit messages. The flaw occurs in the SendUnitData request processing where the length of a connected data item is decremented by 2 without sufficient validation. This underflow leads to an out-of-bounds read or stack buffer overflow during EPATH decoding in functions such as NotifyConnectedCommonPacketFormat and DecodePaddedEPath. A remote, unauthenticated attacker can trigger this by sending a malformed request to TCP port 44818, resulting in a process crash (DoS) or potential remote code execution.

Affected products

  • EIPStackGroup OpENer 2.3.0 (up to commit 76b95cf)

Timeline

  • 2026-05-13: disclosed: Issue reported on GitHub repository
  • 2026-07-09: advisory: Detailed security advisory published by researcher
  • 2026-07-13: advisory: CVE published to NVD dataset

References

Related threats