← Back to search

CVE-2026-71263

9.1 CRITICALpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The flaw in LINUXTCP port of FreeModbus involves an off-by-one error in a bounds check, leading to potential buffer overflow if exploited.
Exploitability
Exploitation requires crafting a specific input that exceeds the buffer size limit, which is moderately difficult given the precise nature of the input needed.
Blast radius
If exploited, this could lead to a denial of service or potentially remote code execution, impacting the integrity and availability of the affected system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the fixed version 1.2.3 or later as published by the vendor.
buffer-overflowmodbusics

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Weaknesses

CWE-787

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.