NULL Pointer Dereference in RT-Labs C-Open CANopen Product
CVE-2026-82357
7.1HIGH
What is CVE-2026-82357?
The C-Open CANopen device by RT-Labs is susceptible to a NULL pointer dereference vulnerability when the LSS protocol is utilized for configuration. This occurs if a user-defined application object lacks the necessary subindexes for object 0x1018. An unauthenticated remote attacker with access to the CAN bus could exploit this flaw, especially via a compromised node, to initiate the LSS protocol on a misconfigured device, potentially leading to a system crash. This issue has been addressed in version 1.1.1.
Affected Version(s)
C-Open 0
C-Open 0 < 1.1.1
C-Open 1.1.1
