Buffer Overflow Vulnerability in MOOS Core-MOOS Software from The MOOS Vendor
CVE-2026-85454
5.2MEDIUM
What is CVE-2026-85454?
The MOOS core-moos software, up to version 10.4.0, is susceptible to a buffer overflow vulnerability due to an off-by-one error occurring in the CMOOSSerialPort::GetTelegram() method. This issue allows attackers with control over the serial line to send a full-length telegram, which can exploit the vulnerability by writing a NUL terminator beyond the allocated stack buffer. Consequently, this can lead to stack corruption and potential unauthorized code execution, posing significant risks to system integrity.
Affected Version(s)
core-moos 0 <= 10.4.0
