Junglewise Threat Intelligence

CVE-2026-85454: MOOS core-moos buffer overflow in CMOOSSerialPort

CVE-2026-85454 · Severity: medium · CVSS 6.1 · Published 2026-09-03

Technologies: MOOS Core-Moos. Vendors: MOOS.

Executive brief

MOOS core-moos is a lightweight middleware platform used to manage real-time communication between software components in robotic and autonomous systems. The vulnerability allows an attacker with access to the serial line to send a specially crafted message that triggers a buffer overflow, potentially corrupting system memory and enabling arbitrary code execution on the affected system.

Technical details

An off-by-one buffer overflow exists in the CMOOSSerialPort::GetTelegram() function in core-moos versions through 10.4.0. The vulnerability occurs when processing incoming serial data: the function fails to properly bound-check the buffer length before writing a NUL terminator, resulting in a write one byte past the allocated stack buffer for the serial telegram. An attacker with control over the serial line can send a full-length telegram to trigger this off-by-one write, corrupting adjacent stack memory. This memory corruption can be exploited to achieve code execution. No patch is mentioned in available sources, and no active exploitation in the wild has been reported.

Affected products

  • MOOS core-moos through 10.4.0

Timeline

  • 2026-09-03: disclosed
  • other: CVE-2026-85454 assigned

References

Related threats