{"id":"CVE-2026-71263","published":"2026-08-05T13:24:50.473","lastModified":"2026-08-10T12:17:28.710","description":"The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","cwes":["CWE-787"],"vendors":[],"products":[],"references":[{"url":"https://github.com/cwalter-at/freemodbus","tags":[]},{"url":"https://github.com/cwalter-at/freemodbus/blob/master/demo/LINUXTCP/port/porttcp.c","tags":[]}],"exploitRefs":[{"url":"https://github.com/cwalter-at/freemodbus","tags":[]},{"url":"https://github.com/cwalter-at/freemodbus/blob/master/demo/LINUXTCP/port/porttcp.c","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw in LINUXTCP port of FreeModbus involves an off-by-one error in a bounds check, leading to potential buffer overflow if exploited.","exploitability":"Exploitation requires crafting a specific input that exceeds the buffer size limit, which is moderately difficult given the precise nature of the input needed.","blast_radius":"If exploited, this could lead to a denial of service or potentially remote code execution, impacting the integrity and availability of the affected system.","remediation":"Upgrade to the fixed version 1.2.3 or later as published by the vendor.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["buffer-overflow","modbus","ics"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:09:30.110Z"}}