CVE-2026-73522
COVESA Open1722 0.9.2 Stack Buffer Overflow via avtp_to_can() in acf-can-listener
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CAN messages. The avtp_to_can() function increments its write index without bounding it against the caller-supplied array size, and because the listener accepts datagrams from any sender matching a hardcoded unauthenticated stream ID transmitted in plaintext, attackers can corrupt adjacent stack memory to achieve arbitrary code execution or denial of service.
| CWE | CWE-121 |
| Vendor | covesa |
| Product | open1722 |
| Published | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for covesa open1722
Be the first to know when new high vulnerabilities affecting covesa open1722 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected Versions
COVESA / Open1722
0 โค 0.9.2
References
Credits
Fatullayev Asadbek