CVE-2026-13196 PUBLISHED

Out-of-bounds Write in KUNBUS piControl

Assigner: Nozomi
Reserved: 24.06.2026 Published: 14.08.2026 Updated: 14.08.2026

Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker with device configuration access to write attacker-controlled data outside the bounds of the process-image buffer and corrupt adjacent kernel memory, resulting in kernel memory corruption and denial of service, by supplying crafted device configuration data and crafted input through the piControl character device.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.3

Product Status

Vendor KUNBUS
Product piControl
Versions Default: unaffected
  • affected from 0 to 2.6.2 (incl.)

Credits

  • Gabriele Quagliarella at Nozomi Networks finder

References

Problem Types

  • CWE-787 Out-of-bounds Write CWE

Impacts

  • CAPEC-123