THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-54410 (HIGH 8.6) — nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte receive buffer by sending a crafted MBAP fram

[NVD] CVE-2026-54410 (HIGH 8.6) — nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte receive buffer by sending a crafted MBAP fram

lownvdPublished 2026-06-14

CVE-2026-54410 CVSS: 8.6 HIGH Published: 2026-06-14T18:17:20.330

nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte receive buffer by sending a crafted MBAP frame whose Length field is set to 255.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54410