Out-of-Bounds Write Vulnerability in KUNBUS piControl Product by Nozomi Networks
CVE-2026-13196

7.3HIGH

Key Information:

Vendor

Kunbus

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-13196?

KUNBUS piControl, a product by Nozomi Networks, is vulnerable due to an out-of-bounds write issue within its process-image management functionality. An attacker with valid local access and device configuration permissions can exploit this flaw by sending crafted input through the piControl character device. This allows for the injection of malicious data outside the designated memory buffers, leading to potential kernel memory corruption and denial of service. Proper precautions are needed to secure configurations and monitor for any unauthorized changes.

Affected Version(s)

piControl 0 <= 2.6.2

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Quagliarella at Nozomi Networks
.