PT-2026-61062 · Davenardella · Snap7

·

CVE-2026-16225

·

Published

2026-07-19

·

Updated

2026-07-19

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions davenardella snap7 versions prior to 1.4.4
Description A security flaw allows for a remote out-of-bounds write, which occurs when the PDULength argument is manipulated within the TSnap7Peer::NegotiatePDULength() function located in the src/core/s7 peer.cpp file.
Recommendations Update davenardella snap7 to version 1.4.4 or later. As a temporary mitigation, restrict access to the TSnap7Peer::NegotiatePDULength() function to prevent remote manipulation of the PDULength argument.

Exploit

Fix

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16225

Affected Products

Snap7