PT-2026-35074 · Unknown · Bacnet Stack

Rasird-Del

·

Published

2026-04-24

·

Updated

2026-04-25

·

CVE-2026-41475

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions BACnet Stack versions prior to 1.4.3
Description An out-of-bounds read exists in the WritePropertyMultiple service decoder. This occurs because the wpm decode object property() function calls the deprecated decode tag number and value() function, which lacks bounds checking on the input buffer. An unauthenticated remote attacker can send a crafted BACnet/IP packet with a truncated property payload to read 1-7 bytes beyond the allocated buffer boundaries, potentially leading to information disclosure or system crashes on embedded devices.
Recommendations Update to version 1.4.3.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41475

Affected Products

Bacnet Stack