Skip to content
CVSS 9.1 · CRITICAL

CVE-2026-41475

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's WritePropertyMultiple service decoder allows unauthenticated remote attackers to read past allocated buffer boundaries by sending a truncated WPM request. The vulnerability stems from wpm_decode_object_property() calling the deprecated decode_tag_number_and_value() function, which performs no bounds checking on the input buffer. A crafted BACnet/IP packet with a truncated property payload causes the decoder to read 1-7 bytes past the end of the buffer, leading to crashes or information disclosure on embedded BACnet devices. This vulnerability is fixed in 1.4.3.

View on NVD

Analysis

This vulnerability affects a specialized C library for the BACnet protocol, which is used in building automation and industrial control systems. While it allows for unauthenticated remote crashes or information disclosure, it falls outside the typical scope of web, mobile, and backend development that the MexicoDev community focuses on.

Severity

Score: 9.1(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: NONE
A: HIGH
Weakness (CWE): CWE-125

EPSS

Probability of exploitation (next 30 days): 0.0027 (0.3%)
Percentile: 49.9%
EPSS: 2026-05-06

Affects

bacnetstack:bacnet_stack

Technical description

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's WritePropertyMultiple service decoder allows unauthenticated remote attackers to read past allocated buffer boundaries by sending a truncated WPM request. The vulnerability stems from wpm_decode_object_property() calling the deprecated decode_tag_number_and_value() function, which performs no bounds checking on the input buffer. A crafted BACnet/IP packet with a truncated property payload causes the decoder to read 1-7 bytes past the end of the buffer, leading to crashes or information disclosure on embedded BACnet devices. This vulnerability is fixed in 1.4.3.

Published: 4/24/2026, 8:16:28 PM
Last modified: 4/28/2026, 3:36:04 PM

References

HomeEventsBlogResourcesTeam