NULL Pointer Dereference in RT-Labs C-Open CANopen Product
CVE-2026-82357

7.1HIGH

Key Information:

Vendor

Rt-labs Ab

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-82357?

The C-Open CANopen device by RT-Labs is susceptible to a NULL pointer dereference vulnerability when the LSS protocol is utilized for configuration. This occurs if a user-defined application object lacks the necessary subindexes for object 0x1018. An unauthenticated remote attacker with access to the CAN bus could exploit this flaw, especially via a compromised node, to initiate the LSS protocol on a misconfigured device, potentially leading to a system crash. This issue has been addressed in version 1.1.1.

Affected Version(s)

C-Open 0

C-Open 0 < 1.1.1

C-Open 1.1.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

f0rw4rd, quellsec.dev
.