PT-2026-84290 · Pyramid Solutions · Ethernet/Ip Adapter Dll Kit+1
CVE-2026-78012
·
Published
2026-09-01
·
Updated
2026-09-04
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NetStaX EtherNet/IP Stack versions prior to 5.6.1
Description
An issue exists where a large Class 3 explicit-message request can exceed the application-side receive buffer without triggering an error or warning. This can lead to memory corruption or a device crash, potentially serving as a remote attack vector since the originating device does not receive a Common Industrial Protocol (CIP) error indicating the request failed. There have been reports of elevated activities targeting the Pyramid Solutions EtherNet IP Adapter DLL Kit and other related products.
Recommendations
Update NetStaX EtherNet/IP Stack to version 5.6.1 or later.
Fix
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ethernet/Ip Adapter Dll Kit
Netstax Ethernet/Ip Stack