SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-51537

CRITICAL · CVSS 9.1 EPSS 0.48% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability in OpENer 2.3.0 allows remote attackers to exploit an out-of-bounds read in the Connection Manager when handling malformed ForwardOpen requests, potentially leading to unauthorized data access or application crashes. This critical flaw can be triggered without authentication, making it particularly dangerous for networked environments. Organizations using this software should prioritize immediate patching or mitigation strategies to protect against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51537
Severity
CRITICAL
CVSS
9.1
EPSS
0.48%

Original NVD Description

EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can send a valid ENIP outer frame carrying a malformed CIP ForwardOpen/LargeForwardOpen request, causing the parser to continue reading fields even when request data is insufficient. This issue is remotely triggerable via network traffic and does not require authentication.

Related CVEs

Other vulnerabilities affecting the same vendor(s)