Search
Find a vulnerability
Search criteria
4 vulnerabilities by RT-Labs AB
CVE-2026-82358 (GCVE-0-2026-82358)
Vulnerability from nvd – Published: 2026-10-01 19:42 – Updated: 2026-10-01 19:42
VLAI
EPSS
VEX
Title
RT-Labs AB C-Open CANopen SDO Server Write Protection Bypass
Summary
RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · cisa-cg (v2.0.3)
Decision recorded 2026-08-28 18:03 UTC
CWE
- CWE-863 - Incorrect Authorization
References
4 references
| URL | Tags |
|---|---|
| https://rt-labs.com/wp-content/uploads/2026/09/RR… | vendor-advisory |
| https://github.com/rtlabs-com/c-open/releases/tag… | release-notes |
| https://raw.githubusercontent.com/cisagov/CSAF/de… | third-party-advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-82358 | vdb-entry |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| RT-Labs AB | C-Open |
Affected:
0 , < 1.1.1
(custom)
Unaffected: 1.1.1 |
Date Public
2026-09-21 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "C-Open",
"vendor": "RT-Labs AB",
"versions": [
{
"lessThan": "1.1.1",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "1.1.1"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "f0rw4rd, quellsec.dev"
}
],
"datePublic": "2026-09-21T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation \u0027src/co_sdo_server.c\u0027 that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
}
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
}
},
{
"other": {
"content": {
"id": "CVE-2026-82358",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-28T18:03:52.879928Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:42:16.559Z",
"orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"shortName": "cisa-cg"
},
"references": [
{
"name": "url",
"tags": [
"vendor-advisory"
],
"url": "https://rt-labs.com/wp-content/uploads/2026/09/RRTL-260929-01.pdf"
},
{
"name": "url",
"tags": [
"release-notes"
],
"url": "https://github.com/rtlabs-com/c-open/releases/tag/public%2Fv1.1.1"
},
{
"name": "url",
"tags": [
"third-party-advisory"
],
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-275-02.json"
},
{
"name": "url",
"tags": [
"vdb-entry"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2026-82358"
}
],
"title": "RT-Labs AB C-Open CANopen SDO Server Write Protection Bypass"
}
},
"cveMetadata": {
"assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"assignerShortName": "cisa-cg",
"cveId": "CVE-2026-82358",
"datePublished": "2026-10-01T19:42:16.559Z",
"dateReserved": "2026-08-28T18:10:39.170Z",
"dateUpdated": "2026-10-01T19:42:16.559Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82357 (GCVE-0-2026-82357)
Vulnerability from nvd – Published: 2026-10-01 19:41 – Updated: 2026-10-01 19:41
VLAI
EPSS
VEX
Title
RT-Labs AB C-Open CANopen NULL pointer dereference
Summary
RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus, through a compromised node for instance, can initiate the LSS protocol on a device with a misconfigured identity object and potentially crash the device. Fixed in 1.1.1.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · cisa-cg (v2.0.3)
Decision recorded 2026-08-28 17:49 UTC
CWE
- CWE-476 - NULL Pointer Dereference
References
4 references
| URL | Tags |
|---|---|
| https://rt-labs.com/wp-content/uploads/2026/09/RR… | vendor-advisory |
| https://github.com/rtlabs-com/c-open/releases/tag… | release-notes |
| https://raw.githubusercontent.com/cisagov/CSAF/de… | third-party-advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-82357 | vdb-entry |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| RT-Labs AB | C-Open |
Affected:
0 , < 1.1.1
(custom)
Unaffected: 1.1.1 |
Date Public
2026-09-21 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "C-Open",
"vendor": "RT-Labs AB",
"versions": [
{
"lessThan": "1.1.1",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "1.1.1"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "f0rw4rd, quellsec.dev"
}
],
"datePublic": "2026-09-21T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus, through a compromised node for instance, can initiate the LSS protocol on a device with a misconfigured identity object and potentially crash the device. Fixed in 1.1.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
},
{
"other": {
"content": {
"id": "CVE-2026-82357",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-28T17:49:30.066195Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-476",
"description": "CWE-476 NULL Pointer Dereference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:41:47.996Z",
"orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"shortName": "cisa-cg"
},
"references": [
{
"name": "url",
"tags": [
"vendor-advisory"
],
"url": "https://rt-labs.com/wp-content/uploads/2026/09/RRTL-260929-01.pdf"
},
{
"name": "url",
"tags": [
"release-notes"
],
"url": "https://github.com/rtlabs-com/c-open/releases/tag/public%2Fv1.1.1"
},
{
"name": "url",
"tags": [
"third-party-advisory"
],
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-275-02.json"
},
{
"name": "url",
"tags": [
"vdb-entry"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2026-82357"
}
],
"title": "RT-Labs AB C-Open CANopen NULL pointer dereference"
}
},
"cveMetadata": {
"assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"assignerShortName": "cisa-cg",
"cveId": "CVE-2026-82357",
"datePublished": "2026-10-01T19:41:47.996Z",
"dateReserved": "2026-08-28T18:10:39.170Z",
"dateUpdated": "2026-10-01T19:41:47.996Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82358 (GCVE-0-2026-82358)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:42 – Updated: 2026-10-01 19:42
VLAI
EPSS
VEX
Title
RT-Labs AB C-Open CANopen SDO Server Write Protection Bypass
Summary
RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · cisa-cg (v2.0.3)
Decision recorded 2026-08-28 18:03 UTC
CWE
- CWE-863 - Incorrect Authorization
References
4 references
| URL | Tags |
|---|---|
| https://rt-labs.com/wp-content/uploads/2026/09/RR… | vendor-advisory |
| https://github.com/rtlabs-com/c-open/releases/tag… | release-notes |
| https://raw.githubusercontent.com/cisagov/CSAF/de… | third-party-advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-82358 | vdb-entry |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| RT-Labs AB | C-Open |
Affected:
0 , < 1.1.1
(custom)
Unaffected: 1.1.1 |
Date Public
2026-09-21 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "C-Open",
"vendor": "RT-Labs AB",
"versions": [
{
"lessThan": "1.1.1",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "1.1.1"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "f0rw4rd, quellsec.dev"
}
],
"datePublic": "2026-09-21T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation \u0027src/co_sdo_server.c\u0027 that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
}
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
}
},
{
"other": {
"content": {
"id": "CVE-2026-82358",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-28T18:03:52.879928Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:42:16.559Z",
"orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"shortName": "cisa-cg"
},
"references": [
{
"name": "url",
"tags": [
"vendor-advisory"
],
"url": "https://rt-labs.com/wp-content/uploads/2026/09/RRTL-260929-01.pdf"
},
{
"name": "url",
"tags": [
"release-notes"
],
"url": "https://github.com/rtlabs-com/c-open/releases/tag/public%2Fv1.1.1"
},
{
"name": "url",
"tags": [
"third-party-advisory"
],
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-275-02.json"
},
{
"name": "url",
"tags": [
"vdb-entry"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2026-82358"
}
],
"title": "RT-Labs AB C-Open CANopen SDO Server Write Protection Bypass"
}
},
"cveMetadata": {
"assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"assignerShortName": "cisa-cg",
"cveId": "CVE-2026-82358",
"datePublished": "2026-10-01T19:42:16.559Z",
"dateReserved": "2026-08-28T18:10:39.170Z",
"dateUpdated": "2026-10-01T19:42:16.559Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82357 (GCVE-0-2026-82357)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:41 – Updated: 2026-10-01 19:41
VLAI
EPSS
VEX
Title
RT-Labs AB C-Open CANopen NULL pointer dereference
Summary
RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus, through a compromised node for instance, can initiate the LSS protocol on a device with a misconfigured identity object and potentially crash the device. Fixed in 1.1.1.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · cisa-cg (v2.0.3)
Decision recorded 2026-08-28 17:49 UTC
CWE
- CWE-476 - NULL Pointer Dereference
References
4 references
| URL | Tags |
|---|---|
| https://rt-labs.com/wp-content/uploads/2026/09/RR… | vendor-advisory |
| https://github.com/rtlabs-com/c-open/releases/tag… | release-notes |
| https://raw.githubusercontent.com/cisagov/CSAF/de… | third-party-advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-82357 | vdb-entry |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| RT-Labs AB | C-Open |
Affected:
0 , < 1.1.1
(custom)
Unaffected: 1.1.1 |
Date Public
2026-09-21 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "C-Open",
"vendor": "RT-Labs AB",
"versions": [
{
"lessThan": "1.1.1",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "1.1.1"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "f0rw4rd, quellsec.dev"
}
],
"datePublic": "2026-09-21T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus, through a compromised node for instance, can initiate the LSS protocol on a device with a misconfigured identity object and potentially crash the device. Fixed in 1.1.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
},
{
"other": {
"content": {
"id": "CVE-2026-82357",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-28T17:49:30.066195Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-476",
"description": "CWE-476 NULL Pointer Dereference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:41:47.996Z",
"orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"shortName": "cisa-cg"
},
"references": [
{
"name": "url",
"tags": [
"vendor-advisory"
],
"url": "https://rt-labs.com/wp-content/uploads/2026/09/RRTL-260929-01.pdf"
},
{
"name": "url",
"tags": [
"release-notes"
],
"url": "https://github.com/rtlabs-com/c-open/releases/tag/public%2Fv1.1.1"
},
{
"name": "url",
"tags": [
"third-party-advisory"
],
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-275-02.json"
},
{
"name": "url",
"tags": [
"vdb-entry"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2026-82357"
}
],
"title": "RT-Labs AB C-Open CANopen NULL pointer dereference"
}
},
"cveMetadata": {
"assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"assignerShortName": "cisa-cg",
"cveId": "CVE-2026-82357",
"datePublished": "2026-10-01T19:41:47.996Z",
"dateReserved": "2026-08-28T18:10:39.170Z",
"dateUpdated": "2026-10-01T19:41:47.996Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}