CVE-2026-67859
7.5 HIGHpublic exploit availablePublished 2026-08-04 · Updated 2026-08-05
AI risk analysis
- Summary
- A buffer overflow vulnerability in open62541 v1.5.5 can be exploited by a remote attacker to cause a denial of service through the Discovery/LDS handling process.
- Exploitability
- Exploitation requires access to the Discovery/LDS handling mechanism, which may be difficult but not impossible for an attacker with network reach.
- Blast radius
- If exploited, this vulnerability could lead to a complete system crash affecting the device or server running open62541 v1.5.5.
- Prioritized remediation
- Update to a patched version of open62541 or apply vendor-provided patches immediately.
buffer-overflowdenial-of-serviceremote-exploitics
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-120
Public exploit & PoC references
- https://github.com/open62541/open62541/blob/master/examples/discovery/server_lds.c
- https://github.com/open62541/open62541/blob/master/src/server/ua_discovery_mdns.c
- https://github.com/open62541/open62541/blob/master/src/server/ua_services_discovery.c
- https://github.com/open62541/open62541/blob/master/src/util/ua_util.c
- https://github.com/open62541/open62541/issues/8095
- https://github.com/open62541/open62541/issues/8095
All references
- https://github.com/open62541/open62541/blob/master/examples/discovery/server_lds.c
- https://github.com/open62541/open62541/blob/master/src/server/ua_discovery_mdns.c
- https://github.com/open62541/open62541/blob/master/src/server/ua_services_discovery.c
- https://github.com/open62541/open62541/blob/master/src/util/ua_util.c
- https://github.com/open62541/open62541/issues/8095
- https://github.com/open62541/open62541/issues/8095
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.