MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line can send a full-length telegram to trigger the off-by-one write, corrupting the stack and potentially enabling code execution.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themoos
Themoos core-moos |
|
| Vendors & Products |
Themoos
Themoos core-moos |
Thu, 03 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line can send a full-length telegram to trigger the off-by-one write, corrupting the stack and potentially enabling code execution. | |
| Title | MOOS core-moos through 10.4.0 Off-by-One Buffer Overflow in Serial Telegram Handling | |
| Weaknesses | CWE-193 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-03T22:38:41.091Z
Updated: 2026-09-08T13:57:18.382Z
Reserved: 2026-09-03T19:51:02.691Z
Link: CVE-2026-85454
Updated: 2026-09-08T13:57:11.789Z
Status : Awaiting Analysis
Published: 2026-09-03T23:17:25.660
Modified: 2026-09-08T20:07:17.943
Link: CVE-2026-85454
No data.