CVE-2026-35085
Stack buffer overflow in method gdv-serverconfig
In short
A user can send specially crafted data to gdv-serverconfig that overflows a memory buffer on the stack, allowing them to take complete control of the system with root privileges.
Technical detail
Stack buffer overflow in gdv-serverconfig (CWE-121) allows an authenticated attacker to overwrite stack memory and execute arbitrary code with root privileges. The vulnerability requires valid user credentials and can be triggered by supplying oversized input to the affected method, bypassing security restrictions.
Summary generated and translated by AI from the official description.
A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
MBS · Double-A ProfibusMBS · Double-A x-linkMBS · Double-X CANMBS · Double-X DALIMBS · Double-X KNXMBS · Double-X LONMBS · Double-X M-BusMBS · Double-X PROFINETMBS · Double-X x-linkMBS · Single-AMBS · Single-XMBS · Triple-X KNX+DALIMBS · Triple-X KNX+LONMBS · Triple-X KNX+M-BusMBS · Triple-X PROFINET+DALIMBS · Triple-X PROFINET+KNXMBS · Triple-X PROFINET+LONMBS · Triple-X PROFINET+M-BusWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →