๐Ÿ” CVE Alert

CVE-2026-71254

CRITICAL 9.8

nanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record()

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record() function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the total request size does not exceed 245 bytes and that each sub-request's record_length is at most 124, but it never validates the CUMULATIVE response size across all sub-requests before processing them. The accumulator response_data_size is declared as uint8_t and is incremented by 2 + record_length*2 for each of up to 35 sub-requests; with 35 sub-requests of record_length=124, the cumulative demand is 8750 bytes, which overflows the uint8_t accumulator. A subsequent loop then calls get_n(), an internal function with no bounds checking, once per sub-request to obtain a pointer into the 260-byte msg.buf receive buffer and advances the internal buf_idx by up to 248 bytes per call; swap_regs() then writes to that pointer unconditionally. A single crafted FC 0x14 request from an unauthenticated network client can cause up to ~8490 bytes to be written out of bounds past the 260-byte buffer, corrupting adjacent memory in the server process and leading to denial of service or potential remote code execution, particularly on embedded/bare-metal targets without memory protection.

CWE CWE-787
Vendor debevv
Product nanomodbus
Published Aug 5, 2026
Last Updated Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for debevv nanomodbus

Be the first to know when new critical vulnerabilities affecting debevv nanomodbus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

debevv / nanoMODBUS
0 โ‰ค 1.23.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/debevv/nanoMODBUS github.com: https://github.com/debevv/nanoMODBUS/blob/master/nanomodbus.c

Credits

Shukhratbek Uraiimov