Write Protection Bypass in RT-Labs AB C-Open CANopen Software
CVE-2026-82358

7.1HIGH

Key Information:

Vendor

Rt-labs Ab

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-82358?

The RT-Labs AB C-Open CANopen software is vulnerable to a write protection bypass due to improper validation of write permissions in its SDO server implementation. An attacker connected to the CAN bus can exploit this vulnerability by initiating an SDO upload on a read-only Object Dictionary entry, allowing them to overwrite critical data without authentication. This issue arises from the failure of the download-segment handler to confirm an active download session before executing write commands. As CANopen lacks inherent authentication mechanisms, it facilitates unauthorized manipulation of memory locations, impacting the integrity of the affected system. The problem has been addressed in version 1.1.1.

Affected Version(s)

C-Open 0

C-Open 0 < 1.1.1

C-Open 1.1.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

f0rw4rd, quellsec.dev
.